{
  "CVE_data_type" : "CVE",
  "CVE_data_format" : "MITRE",
  "CVE_data_version" : "4.0",
  "CVE_data_numberOfCVEs" : "6569",
  "CVE_data_timestamp" : "2020-08-19T08:51Z",
  "CVE_Items" : [ {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0001",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223129",
          "name" : "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223129",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://osvdb.org/33031",
          "name" : "33031",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24300",
          "name" : "24300",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0085.html",
          "name" : "RHSA-2007:0085",
          "refsource" : "REDHAT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22737",
          "name" : "22737",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017705",
          "name" : "1017705",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9560",
          "name" : "oval:org.mitre.oval:def:9560",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that the attacker previously created a watch for a file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:4.0:*:linux_kernel_2.6.9:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.7
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-02T21:18Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0002",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "libwpd",
            "product" : {
              "product_data" : [ {
                "product_name" : "libwpd_library",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://fedoranews.org/cms/node/2805",
          "name" : "FEDORA-2007-350",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=490",
          "name" : "20070316 Multiple Vendor libwpd Multiple Buffer Overflow Vulnerabilities",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html",
          "name" : "SUSE-SA:2007:023",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24465",
          "name" : "24465",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24507",
          "name" : "24507",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24557",
          "name" : "24557",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24572",
          "name" : "24572",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24573",
          "name" : "24573",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24580",
          "name" : "24580",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24581",
          "name" : "24581",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24588",
          "name" : "24588",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24591",
          "name" : "24591",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24593",
          "name" : "24593",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24613",
          "name" : "24613",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24794",
          "name" : "24794",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24856",
          "name" : "24856",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24906",
          "name" : "24906",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200704-07.xml",
          "name" : "GLSA-200704-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.399659",
          "name" : "SSA-2007-085-02",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=494122",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=494122",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102863-1",
          "name" : "102863",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1268",
          "name" : "DSA-1268",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1270",
          "name" : "DSA-1270",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml",
          "name" : "GLSA-200704-12",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:063",
          "name" : "MDKSA-2007:063",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:064",
          "name" : "MDKSA-2007:064",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0055.html",
          "name" : "RHSA-2007:0055",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/463033/100/0/threaded",
          "name" : "20070316 rPSA-2007-0057-1 libwpd",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23006",
          "name" : "23006",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017789",
          "name" : "1017789",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-437-1",
          "name" : "USN-437-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0976",
          "name" : "ADV-2007-0976",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1032",
          "name" : "ADV-2007-1032",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1339",
          "name" : "ADV-2007-1339",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11535",
          "name" : "oval:org.mitre.oval:def:11535",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file in which values to loop counters are not properly handled in the (1) WP3TablesGroup::_readContents and (2) WP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup functions.  NOTE: the integer overflow has been split into CVE-2007-1466."
        }, {
          "lang" : "en",
          "value" : "This vulnerability has been addressed by the vendor through a product update: http://sourceforge.net/projects/libwpd/"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libwpd:libwpd_library:0.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libwpd:libwpd_library:0.8.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libwpd:libwpd_library:0.8.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libwpd:libwpd_library:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.8.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-16T21:19Z",
    "lastModifiedDate" : "2018-10-16T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0003",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "andrew_morgan",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_pam",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.99.7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32017",
          "name" : "32017",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23858",
          "name" : "23858",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_3_sr.html",
          "name" : "SUSE-SR:2007:003",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01271.html",
          "name" : "[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes",
          "refsource" : "MLIST",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01277.html",
          "name" : "[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes",
          "refsource" : "MLIST",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22204",
          "name" : "22204",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0323",
          "name" : "ADV-2007-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31739",
          "name" : "linuxpam-pamunix-security-bypass(31739)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.redhat.com/archives/pam-list/2007-January/msg00017.html",
          "name" : "[pam-list] 20070123 Linux-PAM 0.99.7.1 released",
          "refsource" : "MLIST",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:andrew_morgan:linux_pam:0.99.7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T21:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0004",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=199715",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=199715",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The NFS client implementation in the kernel in Red Hat Enterprise Linux (RHEL) 3, when a filesystem is mounted with the noacl option, checks permissions for the open system call via vfs_permission (mode bits) data rather than an NFS ACCESS call to the server, which allows local client processes to obtain a false success status from open calls that the server would deny, and possibly obtain sensitive information about file permissions on the server, as demonstrated in a root_squash environment.  NOTE: it is uncertain whether any scenarios involving this issue cross privilege boundaries."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-09-18T19:17Z",
    "lastModifiedDate" : "2008-09-05T21:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0005",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "omnikey.aaitg",
            "product" : {
              "product_data" : [ {
                "product_name" : "omnikey_cardman_4040",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://fedoranews.org/cms/node/2787",
          "name" : "FEDORA-2007-335",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2788",
          "name" : "FEDORA-2007-336",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3",
          "name" : "http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24436",
          "name" : "24436",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24518",
          "name" : "24518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24777",
          "name" : "24777",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24901",
          "name" : "24901",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25078",
          "name" : "25078",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25691",
          "name" : "25691",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26133",
          "name" : "26133",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26139",
          "name" : "26139",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1286",
          "name" : "DSA-1286",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:078",
          "name" : "MDKSA-2007:078",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33023",
          "name" : "33023",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0099.html",
          "name" : "RHSA-2007:0099",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/462300/100/0/threaded",
          "name" : "20070309 Buffer Overflow in Linux Drivers for Omnikey CardMan 4040 (CVE-2007-0005)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/471457",
          "name" : "20070615 rPSA-2007-0124-1 kernel xen",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22870",
          "name" : "22870",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-486-1",
          "name" : "USN-486-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-489-1",
          "name" : "USN-489-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0872",
          "name" : "ADV-2007-0872",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32880",
          "name" : "kernel-cardman4040drivers-bo(32880)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1035",
          "name" : "https://issues.rpath.com/browse/RPL-1035",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11238",
          "name" : "oval:org.mitre.oval:def:11238",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21:rc1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:rc2:*:*:*:*:*:*",
            "versionEndIncluding" : "2.6.21"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.21.7:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:omnikey.aaitg:omnikey_cardman_4040:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-10T00:19Z",
    "lastModifiedDate" : "2018-10-16T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0006",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugzilla.kernel.org/show_bug.cgi?id=7727",
          "name" : "http://bugzilla.kernel.org/show_bug.cgi?id=7727",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24109",
          "name" : "24109",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24259",
          "name" : "24259",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24300",
          "name" : "24300",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24429",
          "name" : "24429",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24482",
          "name" : "24482",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24547",
          "name" : "24547",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24752",
          "name" : "24752",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25691",
          "name" : "25691",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:047",
          "name" : "MDKSA-2007:047",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:060",
          "name" : "MDKSA-2007:060",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_21_kernel.html",
          "name" : "SUSE-SA:2007:021",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0085.html",
          "name" : "RHSA-2007:0085",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0099.html",
          "name" : "RHSA-2007:0099",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/471457",
          "name" : "20070615 rPSA-2007-0124-1 kernel xen",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22539",
          "name" : "22539",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-451-1",
          "name" : "USN-451-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1097",
          "name" : "https://issues.rpath.com/browse/RPL-1097",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9829",
          "name" : "oval:org.mitre.oval:def:9829",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as \"spinlock CPU recursion.\""
        }, {
          "lang" : "en",
          "value" : "The scheme for selecting serial numbers was changed from incrementing a counter to random number selection, increasing the likelihood of a serial number collision."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.6.20"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0007",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnucash",
            "product" : {
              "product_data" : [ {
                "product_name" : "gnucash",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://fedoranews.org/cms/node/2725",
          "name" : "FEDORA-2007-256",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24225",
          "name" : "24225",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24226",
          "name" : "24226",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24317",
          "name" : "24317",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=192&release_id=487446",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=192&release_id=487446",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:046",
          "name" : "MDKSA-2007:046",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22610",
          "name" : "22610",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0653",
          "name" : "ADV-2007-0653",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223233",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223233",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32558",
          "name" : "gnucash-symlink(32558)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "gnucash 2.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) gnucash.trace, (2) qof.trace, and (3) qof.trace.[PID] temporary files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnucash:gnucash:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-20T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0008",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "network_security_services",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.11.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc",
          "name" : "20070202-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc",
          "name" : "20070301-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2709",
          "name" : "FEDORA-2007-278",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2711",
          "name" : "FEDORA-2007-279",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2713",
          "name" : "FEDORA-2007-281",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2728",
          "name" : "FEDORA-2007-293",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2747",
          "name" : "FEDORA-2007-308",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2749",
          "name" : "FEDORA-2007-309",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742",
          "name" : "HPSBUX02153",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482",
          "name" : "20070223 Mozilla Network Security Services SSLv2 Client Integer Underflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html",
          "name" : "SUSE-SA:2007:019",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0077.html",
          "name" : "RHSA-2007:0077",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24205",
          "name" : "24205",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24238",
          "name" : "24238",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24252",
          "name" : "24252",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24253",
          "name" : "24253",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24277",
          "name" : "24277",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24287",
          "name" : "24287",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24290",
          "name" : "24290",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24293",
          "name" : "24293",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24320",
          "name" : "24320",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24328",
          "name" : "24328",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24333",
          "name" : "24333",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24342",
          "name" : "24342",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24343",
          "name" : "24343",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24384",
          "name" : "24384",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24389",
          "name" : "24389",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24395",
          "name" : "24395",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24406",
          "name" : "24406",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24410",
          "name" : "24410",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24455",
          "name" : "24455",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24456",
          "name" : "24456",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24457",
          "name" : "24457",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24522",
          "name" : "24522",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24562",
          "name" : "24562",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24650",
          "name" : "24650",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24703",
          "name" : "24703",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25588",
          "name" : "25588",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25597",
          "name" : "25597",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-18.xml",
          "name" : "GLSA-200703-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131",
          "name" : "SSA:2007-066-05",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947",
          "name" : "SSA:2007-066-04",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851",
          "name" : "SSA:2007-066-03",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1",
          "name" : "102856",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1",
          "name" : "102945",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1336",
          "name" : "DSA-1336",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml",
          "name" : "GLSA-200703-22",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/377812",
          "name" : "VU#377812",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:050",
          "name" : "MDKSA-2007:050",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:052",
          "name" : "MDKSA-2007:052",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2007/mfsa2007-06.html",
          "name" : "http://www.mozilla.org/security/announce/2007/mfsa2007-06.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_22_mozilla.html",
          "name" : "SUSE-SA:2007:022",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32105",
          "name" : "32105",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0078.html",
          "name" : "RHSA-2007:0078",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0079.html",
          "name" : "RHSA-2007:0079",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0097.html",
          "name" : "RHSA-2007:0097",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0108.html",
          "name" : "RHSA-2007:0108",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461336/100/0/threaded",
          "name" : "20070226 rPSA-2007-0040-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461809/100/0/threaded",
          "name" : "20070303 rPSA-2007-0040-3 firefox thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22694",
          "name" : "22694",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/64758",
          "name" : "64758",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017696",
          "name" : "1017696",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-428-1",
          "name" : "USN-428-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-431-1",
          "name" : "USN-431-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0718",
          "name" : "ADV-2007-0718",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0719",
          "name" : "ADV-2007-0719",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1165",
          "name" : "ADV-2007-1165",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2141",
          "name" : "ADV-2007-2141",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=364319",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=364319",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32666",
          "name" : "nss-mastersecret-bo(32666)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1081",
          "name" : "https://issues.rpath.com/browse/RPL-1081",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1103",
          "name" : "https://issues.rpath.com/browse/RPL-1103",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10502",
          "name" : "oval:org.mitre.oval:def:10502",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the \"Master Secret\", which results in a heap-based overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9:rc:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0:preview_release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0.9"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:network_security_services:3.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:network_security_services:3.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:network_security_services:3.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-26T20:28Z",
    "lastModifiedDate" : "2018-10-16T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0009",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "network_security_services",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.11.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc",
          "name" : "20070202-01-P",
          "refsource" : "SGI",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc",
          "name" : "20070301-01-P",
          "refsource" : "SGI",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2709",
          "name" : "FEDORA-2007-278",
          "refsource" : "FEDORA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2711",
          "name" : "FEDORA-2007-279",
          "refsource" : "FEDORA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2747",
          "name" : "FEDORA-2007-308",
          "refsource" : "FEDORA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2749",
          "name" : "FEDORA-2007-309",
          "refsource" : "FEDORA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742",
          "name" : "HPSBUX02153",
          "refsource" : "HP",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483",
          "name" : "20070223 Mozilla Network Security Services SSLv2 Server Stack Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html",
          "name" : "SUSE-SA:2007:019",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0077.html",
          "name" : "RHSA-2007:0077",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24253",
          "name" : "24253",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24277",
          "name" : "24277",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24287",
          "name" : "24287",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24290",
          "name" : "24290",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24293",
          "name" : "24293",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24333",
          "name" : "24333",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24342",
          "name" : "24342",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24343",
          "name" : "24343",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24384",
          "name" : "24384",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24389",
          "name" : "24389",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24395",
          "name" : "24395",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24406",
          "name" : "24406",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24410",
          "name" : "24410",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24455",
          "name" : "24455",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24456",
          "name" : "24456",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24457",
          "name" : "24457",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24522",
          "name" : "24522",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24562",
          "name" : "24562",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24650",
          "name" : "24650",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24703",
          "name" : "24703",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25588",
          "name" : "25588",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25597",
          "name" : "25597",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-18.xml",
          "name" : "GLSA-200703-18",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131",
          "name" : "SSA:2007-066-05",
          "refsource" : "SLACKWARE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947",
          "name" : "SSA:2007-066-04",
          "refsource" : "SLACKWARE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851",
          "name" : "SSA:2007-066-03",
          "refsource" : "SLACKWARE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1",
          "name" : "102856",
          "refsource" : "SUNALERT",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1",
          "name" : "102945",
          "refsource" : "SUNALERT",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1336",
          "name" : "DSA-1336",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml",
          "name" : "GLSA-200703-22",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/592796",
          "name" : "VU#592796",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:050",
          "name" : "MDKSA-2007:050",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:052",
          "name" : "MDKSA-2007:052",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2007/mfsa2007-06.html",
          "name" : "http://www.mozilla.org/security/announce/2007/mfsa2007-06.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_22_mozilla.html",
          "name" : "SUSE-SA:2007:022",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/32106",
          "name" : "32106",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0078.html",
          "name" : "RHSA-2007:0078",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0079.html",
          "name" : "RHSA-2007:0079",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0097.html",
          "name" : "RHSA-2007:0097",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0108.html",
          "name" : "RHSA-2007:0108",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461336/100/0/threaded",
          "name" : "20070226 rPSA-2007-0040-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461809/100/0/threaded",
          "name" : "20070303 rPSA-2007-0040-3 firefox thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/64758",
          "name" : "64758",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017696",
          "name" : "1017696",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-428-1",
          "name" : "USN-428-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-431-1",
          "name" : "USN-431-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0718",
          "name" : "ADV-2007-0718",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0719",
          "name" : "ADV-2007-0719",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1165",
          "name" : "ADV-2007-1165",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2141",
          "name" : "ADV-2007-2141",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=364323",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=364323",
          "refsource" : "MISC",
          "tags" : [ "Issue Tracking", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32663",
          "name" : "nss-clientmasterkey-bo(32663)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1081",
          "name" : "https://issues.rpath.com/browse/RPL-1081",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1103",
          "name" : "https://issues.rpath.com/browse/RPL-1103",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10174",
          "name" : "oval:org.mitre.oval:def:10174",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid \"Client Master Key\" length values."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.5",
          "versionEndExcluding" : "1.5.0.10"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0",
          "versionEndExcluding" : "2.0.0.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "3.11.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "1.0.8"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "1.5.0.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-26T20:28Z",
    "lastModifiedDate" : "2019-10-09T22:51Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0010",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "the_gimp_team",
            "product" : {
              "product_data" : [ {
                "product_name" : "gimp_toolkit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31621",
          "name" : "31621",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23884",
          "name" : "23884",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23933",
          "name" : "23933",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23935",
          "name" : "23935",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23984",
          "name" : "23984",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24006",
          "name" : "24006",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24010",
          "name" : "24010",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24095",
          "name" : "24095",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017552",
          "name" : "1017552",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:039",
          "name" : "MDKSA-2007:039",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_02_sr.html",
          "name" : "SUSE-SR:2007:002",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0019.html",
          "name" : "RHSA-2007:0019",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22209",
          "name" : "22209",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-415-1",
          "name" : "USN-415-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0331",
          "name" : "ADV-2007-0331",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218932",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218932",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-984",
          "name" : "https://issues.rpath.com/browse/RPL-984",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10325",
          "name" : "oval:org.mitre.oval:def:10325",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.debian.org/security/2007/dsa-1256",
          "name" : "DSA-1256",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:the_gimp_team:gimp_toolkit:2.4.12:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-24T19:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0011",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "citrix",
            "product" : {
              "product_data" : [ {
                "product_name" : "access_gateway",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/45288",
          "name" : "45288",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26143",
          "name" : "26143",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1018435",
          "name" : "1018435",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.citrix.com/article/CTX112803",
          "name" : "http://support.citrix.com/article/CTX112803",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.citrix.com/article/CTX113814",
          "name" : "http://support.citrix.com/article/CTX113814",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/482626/100/100/threaded",
          "name" : "20071022 Corsaire Security Advisory - Citrix Access Gateway session ID disclosure issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24975",
          "name" : "24975",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2583",
          "name" : "ADV-2007-2583",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/35510",
          "name" : "citrix-access-unspeci-information-disclosure(35510)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading \"residual information\", including the a referer log, browser history, or browser cache."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:citrix:access_gateway:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:citrix:access_gateway:4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:citrix:access_gateway:4.5:*:advanced:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:citrix:access_gateway:4.5:*:standard:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-11-05T17:46Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0012",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/3527",
          "name" : "3527",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485942/100/0/threaded",
          "name" : "20080108 Corsaire Security Advisory: Sun J2RE DoS issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27185",
          "name" : "27185",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39549",
          "name" : "sun-java-jpiexp32-dos(39549)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update10:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update11:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update12:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update13:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update7:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update8:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update9:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-01-09T23:46Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0014",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "chainkey_java_code_protection",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-310"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33473",
          "name" : "33473",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456712/100/0/threaded",
          "name" : "20070112 Corsaire Security Advisory: ChainKey Java Code Protection Bypass issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456734/100/0/threaded",
          "name" : "20070112 Re: Corsaire Security Advisory: ChainKey Java Code Protection Bypass issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ChainKey Java Code Protection allows attackers to decompile Java class files via a Java class loader with a modified defineClass method that saves the bytecode to a file before it is passed to the JVM."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:chainkey_java_code_protection:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0015",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=304989",
          "name" : "http://docs.info.apple.com/article.html?artnum=304989",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://isc.sans.org/diary.html?storyid=2094",
          "name" : "http://isc.sans.org/diary.html?storyid=2094",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html",
          "name" : "http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Jan/msg00000.html",
          "name" : "APPLE-SA-2007-01-23",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-01-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-01-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/23540",
          "name" : "23540",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/blog/7/",
          "name" : "http://secunia.com/blog/7/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017461",
          "name" : "1017461",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/442497",
          "name" : "VU#442497",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31023",
          "name" : "31023",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21829",
          "name" : "21829",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-005A.html",
          "name" : "TA07-005A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0001",
          "name" : "ADV-2007-0001",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31203",
          "name" : "quicktime-rtsp-url-bo(31203)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3064",
          "name" : "3064",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-01T23:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0016",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "netfarer",
            "product" : {
              "product_data" : [ {
                "product_name" : "movieplay",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.76",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32547",
          "name" : "32547",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22959",
          "name" : "22959",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21840",
          "name" : "21840",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/4051",
          "name" : "4051",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a LST file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netfarer:movieplay:4.76:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-03T02:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0017",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "videolan",
            "product" : {
              "product_data" : [ {
                "product_name" : "vlc_media_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.4a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://applefun.blogspot.com/2007/01/moab-02-01-2007-vlc-media-player-udp.html",
          "name" : "http://applefun.blogspot.com/2007/01/moab-02-01-2007-vlc-media-player-udp.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://landonf.bikemonkey.org/code/macosx/MOAB_Day_2.20070103045559.6753.timor.html",
          "name" : "http://landonf.bikemonkey.org/code/macosx/MOAB_Day_2.20070103045559.6753.timor.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31163",
          "name" : "31163",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-02-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-02-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23592",
          "name" : "23592",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23829",
          "name" : "23829",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23910",
          "name" : "23910",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23971",
          "name" : "23971",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200701-24.xml",
          "name" : "GLSA-200701-24",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017464",
          "name" : "1017464",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://trac.videolan.org/vlc/changeset/18481",
          "name" : "http://trac.videolan.org/vlc/changeset/18481",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1252",
          "name" : "DSA-1252",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_13_xine.html",
          "name" : "SUSE-SA:2007:013",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21852",
          "name" : "21852",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.via.ecp.fr/via/ml/vlc-devel/2007-01/msg00005.html",
          "name" : "[vlc-devel] 20070102 Security hole in VLC media player for Mac...",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.videolan.org/patches/vlc-0.8.6-MOAB-02-01-2007.patch",
          "name" : "http://www.videolan.org/patches/vlc-0.8.6-MOAB-02-01-2007.patch",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.videolan.org/sa0701.html",
          "name" : "http://www.videolan.org/sa0701.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0026",
          "name" : "ADV-2007-0026",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31226",
          "name" : "vlcmediaplayer-udp-format-string(31226)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14313",
          "name" : "oval:org.mitre.oval:def:14313",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:0.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:0.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:0.8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:0.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:0.8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:0.8.4a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:0.8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:0.8.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-03T02:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0018",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "altdo",
            "product" : {
              "product_data" : [ {
                "product_name" : "convert_mp3_master",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mp3_record_and_edit_audio_master",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "americanshareware",
            "product" : {
              "product_data" : [ {
                "product_name" : "mp3_wav_converter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "audio_edit_magic",
            "product" : {
              "product_data" : [ {
                "product_name" : "audio_edit_magic",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.3_389",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "bearshare",
            "product" : {
              "product_data" : [ {
                "product_name" : "bearshare",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.2.26789",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "cdburnerxp",
            "product" : {
              "product_data" : [ {
                "product_name" : "cdburnerxp_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.116",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "cheetahburner",
            "product" : {
              "product_data" : [ {
                "product_name" : "cheetah_cd_burner",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.56",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cheetah_dvd_burner",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.79",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "code-it_softare",
            "product" : {
              "product_data" : [ {
                "product_name" : "abasic_editor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "wave_mp3_editor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "dandans_digital_media_products",
            "product" : {
              "product_data" : [ {
                "product_name" : "easy_audio_editor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "full_audio_converter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "music_editing_master",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "visual_video_converter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "digital_borneo",
            "product" : {
              "product_data" : [ {
                "product_name" : "audio_mixer_and_editor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "easy_ringtone_maker",
            "product" : {
              "product_data" : [ {
                "product_name" : "easy_ringtone_maker",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "expstudio",
            "product" : {
              "product_data" : [ {
                "product_name" : "audio_editor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "iaudiosoft.com",
            "product" : {
              "product_data" : [ {
                "product_name" : "absolute_mp3_splitter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "absolute_sound_recorder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "absolute_video_to_audio_converter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "imesh.com",
            "product" : {
              "product_data" : [ {
                "product_name" : "imesh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.2.26789",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "j_hepple_products",
            "product" : {
              "product_data" : [ {
                "product_name" : "fx_audio_concat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.0_beta",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "fx_audio_editor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "fx_audio_tools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "fx_magic_music",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "fx_movie_joiner",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.2.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "fx_movie_joiner_and_splitter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.2.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "fx_movie_splitter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.4.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "fx_new_sound",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "fx_video_converter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.51.21",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "joshua_mediasoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "audio_convertor_plus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "video_converter_plus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "magicvideosoftare",
            "product" : {
              "product_data" : [ {
                "product_name" : "magic_audio_converter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2.6_build_719",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "magic_audio_recorder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "magic_music_editor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mcfunsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "audio_editor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3.3_build_489",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "audio_recorder_for_free",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "audio_studio",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.6.3_build_479",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ipod_audio_studio",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.2.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ipod_music_converter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "recording_to_ipod_solution",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mediatox",
            "product" : {
              "product_data" : [ {
                "product_name" : "aurora_media_workshop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.25",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "movavi",
            "product" : {
              "product_data" : [ {
                "product_name" : "chiliburner",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "convertmovie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "dvd_to_ipod",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "splitmovie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "videomessage",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mp3-soft",
            "product" : {
              "product_data" : [ {
                "product_name" : "mp3_normalizer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.03",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mystik_media_products",
            "product" : {
              "product_data" : [ {
                "product_name" : "audioedit_deluxe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "blaze_media_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "blaze_mediaconvert",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "contextconvert_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "nctsoft_products",
            "product" : {
              "product_data" : [ {
                "product_name" : "nctaudioeditor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "nctaudiofile2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "nctaudiostudio",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "nctdialogicvoice",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "nextlevel_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "audio_editor_gold",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.5_build_424",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "audio_studio_gold",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.1.1_build_500",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "quikscribe",
            "product" : {
              "product_data" : [ {
                "product_name" : "quikscribe_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.022.05",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "quikscribe_recorder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.021.29",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "recordnrip",
            "product" : {
              "product_data" : [ {
                "product_name" : "recordnrip",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "rmbsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "audioconvert",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.0.125",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "soundedit_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "roemer_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "easy_hi-q_converter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "easy_hi-q_recorder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "free_hi-q_recorder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "sienzo",
            "product" : {
              "product_data" : [ {
                "product_name" : "digital_music_mentor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "smart_media_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "power_audio_editor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "softdiv_softare",
            "product" : {
              "product_data" : [ {
                "product_name" : "dexster",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ivideomax",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mp3_to_wav_converter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "snosh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "videozilla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "virtual_cd",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_cd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "virtual_cd_file_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "xrlly_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "arial_audio_converter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.40",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "arial_sound_recorder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "text_to_speech_maker",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "xwaver.com",
            "product" : {
              "product_data" : [ {
                "product_name" : "magic_audio_editor_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.1_build_476",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "magic_music_studio_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.2.1_build_500",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/22922",
          "name" : "22922",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23475",
          "name" : "23475",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23485",
          "name" : "23485",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23493",
          "name" : "23493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23495",
          "name" : "23495",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23511",
          "name" : "23511",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23516",
          "name" : "23516",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23530",
          "name" : "23530",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23532",
          "name" : "23532",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23534",
          "name" : "23534",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23535",
          "name" : "23535",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23536",
          "name" : "23536",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23541",
          "name" : "23541",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23542",
          "name" : "23542",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23543",
          "name" : "23543",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23544",
          "name" : "23544",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23546",
          "name" : "23546",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23548",
          "name" : "23548",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23550",
          "name" : "23550",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23551",
          "name" : "23551",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23552",
          "name" : "23552",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23553",
          "name" : "23553",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23554",
          "name" : "23554",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23557",
          "name" : "23557",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23558",
          "name" : "23558",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23560",
          "name" : "23560",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23561",
          "name" : "23561",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23562",
          "name" : "23562",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23565",
          "name" : "23565",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23568",
          "name" : "23568",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23745",
          "name" : "23745",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23753",
          "name" : "23753",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23795",
          "name" : "23795",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25993",
          "name" : "25993",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26046",
          "name" : "26046",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26100",
          "name" : "26100",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26101",
          "name" : "26101",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28407",
          "name" : "28407",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30406",
          "name" : "30406",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30424",
          "name" : "30424",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30439",
          "name" : "30439",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30446",
          "name" : "30446",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30447",
          "name" : "30447",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30450",
          "name" : "30450",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30459",
          "name" : "30459",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/blog/6/",
          "name" : "http://secunia.com/blog/6/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-10/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-10/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-11/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-11/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-12/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-12/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-13/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-13/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-14/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-14/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-15/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-15/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-16/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-16/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-17/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-17/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-18/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-18/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-19/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-19/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-2/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-2/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-20/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-20/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-21/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-21/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-22/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-22/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-23/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-23/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-24/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-24/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-25/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-25/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-26/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-26/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-27/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-27/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-28/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-28/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-29/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-29/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-3/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-3/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-30/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-30/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-31/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-31/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-32/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-32/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-33/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-33/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-34/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-34/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-4/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-4/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-5/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-5/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-50/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-50/advisory/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-6/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-6/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-7/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-7/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-8/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-8/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-9/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-9/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/292713",
          "name" : "VU#292713",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457936/100/200/threaded",
          "name" : "20070124 Secunia Research: NCTsoft Products NCTAudioFile2 ActiveX ControlBuffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457940/100/200/threaded",
          "name" : "20070124 Secunia Research: Sienzo Digital Music Mentor NCTAudioFile2ActiveX Control Buffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457965/100/200/threaded",
          "name" : "20070124 Re: Secunia Research: NCTsoft Products NCTAudioFile2 ActiveXControl Buffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22196",
          "name" : "22196",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23892",
          "name" : "23892",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0310",
          "name" : "ADV-2007-0310",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31707",
          "name" : "nctaudiofile2-multiple-bo(31707)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:altdo:convert_mp3_master:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:altdo:mp3_record_and_edit_audio_master:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:americanshareware:mp3_wav_converter:3.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:audio_edit_magic:audio_edit_magic:9.2.3_389:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bearshare:bearshare:6.0.2.26789:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cdburnerxp:cdburnerxp_pro:3.0.116:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cheetahburner:cheetah_cd_burner:3.56:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cheetahburner:cheetah_dvd_burner:1.79:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:code-it_softare:abasic_editor:10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:code-it_softare:wave_mp3_editor:10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dandans_digital_media_products:easy_audio_editor:7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dandans_digital_media_products:full_audio_converter:4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dandans_digital_media_products:music_editing_master:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dandans_digital_media_products:visual_video_converter:4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:digital_borneo:audio_mixer_and_editor:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:easy_ringtone_maker:easy_ringtone_maker:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:expstudio:audio_editor:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:iaudiosoft.com:absolute_mp3_splitter:2.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:iaudiosoft.com:absolute_sound_recorder:3.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:iaudiosoft.com:absolute_video_to_audio_converter:2.7.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:imesh.com:imesh:7.0.2.26789:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:j_hepple_products:fx_audio_concat:1.2.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:j_hepple_products:fx_audio_editor:4.7.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:j_hepple_products:fx_audio_tools:7.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:j_hepple_products:fx_magic_music:5.7.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:j_hepple_products:fx_movie_joiner:6.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:j_hepple_products:fx_movie_joiner_and_splitter:6.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:j_hepple_products:fx_movie_splitter:6.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:j_hepple_products:fx_new_sound:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:j_hepple_products:fx_video_converter:7.51.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joshua_mediasoft:audio_convertor_plus:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joshua_mediasoft:video_converter_plus:3.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:magicvideosoftare:magic_audio_converter:8.2.6_build_719:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:magicvideosoftare:magic_audio_recorder:5.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:magicvideosoftare:magic_music_editor:5.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mcfunsoft:audio_editor:6.3.3_build_489:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mcfunsoft:audio_recorder_for_free:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mcfunsoft:audio_studio:6.6.3_build_479:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mcfunsoft:ipod_audio_studio:6.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mcfunsoft:ipod_music_converter:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mcfunsoft:recording_to_ipod_solution:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediatox:aurora_media_workshop:3.3.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:movavi:chiliburner:2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:movavi:convertmovie:4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:movavi:dvd_to_ipod:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:movavi:splitmovie:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:movavi:suite:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:movavi:videomessage:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mp3-soft:mp3_normalizer:1.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mystik_media_products:audioedit_deluxe:4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mystik_media_products:blaze_media_pro:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mystik_media_products:blaze_mediaconvert:3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mystik_media_products:contextconvert_pro:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nctsoft_products:nctaudioeditor:2.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nctsoft_products:nctaudiofile2:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nctsoft_products:nctaudiostudio:2.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nctsoft_products:nctdialogicvoice:2.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nextlevel_systems:audio_editor_gold:9.2.5_build_424:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nextlevel_systems:audio_studio_gold:7.0.1.1_build_500:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:quikscribe:quikscribe_player:5.022.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:quikscribe:quikscribe_recorder:5.021.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:recordnrip:recordnrip:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rmbsoft:audioconvert:3.1.0.125:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rmbsoft:soundedit_pro:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:roemer_software:easy_hi-q_converter:1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:roemer_software:easy_hi-q_recorder:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:roemer_software:free_hi-q_recorder:1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sienzo:digital_music_mentor:2.6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smart_media_systems:power_audio_editor:11.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:softdiv_softare:dexster:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:softdiv_softare:ivideomax:3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:softdiv_softare:mp3_to_wav_converter:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:softdiv_softare:snosh:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:softdiv_softare:videozilla:2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_cd:virtual_cd:6.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_cd:virtual_cd:7.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_cd:virtual_cd:8.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_cd:virtual_cd_file_server:7.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xrlly_software:arial_audio_converter:2.3.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xrlly_software:arial_sound_recorder:1.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xrlly_software:text_to_speech_maker:1.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xwaver.com:magic_audio_editor_pro:10.3.1_build_476:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xwaver.com:magic_music_studio_pro:7.0.2.1_build_500:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-24T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0019",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "maxum_development_corporation",
            "product" : {
              "product_data" : [ {
                "product_name" : "rumpus_ftp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32689",
          "name" : "32689",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32692",
          "name" : "32692",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-18-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-18-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23842",
          "name" : "23842",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31594",
          "name" : "rumpus-ftp-http-bo(31594)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecified requests to the FTP service, and (2) allow remote attackers to execute arbitrary code via unspecified requests to the HTTP service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maxum_development_corporation:rumpus_ftp_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T21:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0020",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "panic_transmit",
            "product" : {
              "product_data" : [ {
                "product_name" : "panic_transmit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32694",
          "name" : "32694",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-19-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-19-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23861",
          "name" : "23861",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22145",
          "name" : "22145",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0273",
          "name" : "ADV-2007-0273",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31673",
          "name" : "transmit-url-handler-bo(31673)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3160",
          "name" : "3160",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:panic_transmit:panic_transmit:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.5.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-24T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0021",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "ichat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305102",
          "name" : "http://docs.info.apple.com/article.html?artnum=305102",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html",
          "name" : "APPLE-SA-2007-02-15",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32715",
          "name" : "32715",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-20-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-20-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24198",
          "name" : "24198",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/794752",
          "name" : "VU#794752",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22146",
          "name" : "22146",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017661",
          "name" : "1017661",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-047A.html",
          "name" : "TA07-047A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0274",
          "name" : "ADV-2007-0274",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31679",
          "name" : "ichat-aim-format-string(31679)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:ichat:3.1.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0022",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-21-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-21-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23793",
          "name" : "23793",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/31605",
          "name" : "31605",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22148",
          "name" : "22148",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017941",
          "name" : "1017941",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0074",
          "name" : "ADV-2007-0074",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31677",
          "name" : "macos-writeconfig-privilege-escalation(31677)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to a malicious launchctl program."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0023",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305102",
          "name" : "http://docs.info.apple.com/article.html?artnum=305102",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html",
          "name" : "APPLE-SA-2007-02-15",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-22-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-22-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23846",
          "name" : "23846",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24198",
          "name" : "24198",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017542",
          "name" : "1017542",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/315856",
          "name" : "VU#315856",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/32695",
          "name" : "32695",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22188",
          "name" : "22188",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-047A.html",
          "name" : "TA07-047A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0074",
          "name" : "ADV-2007-0074",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31676",
          "name" : "macos-inputmanager-privilege-escalation(31676)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed when Cocoa applications attempt to notify the user."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-24T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0024",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=462",
          "name" : "20070109 Microsoft Windows VML Element Integer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23677",
          "name" : "23677",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017489",
          "name" : "1017489",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-009.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-009.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.microsoft.com/?kbid=929969",
          "name" : "929969",
          "refsource" : "MSKB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/122084",
          "name" : "VU#122084",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31250",
          "name" : "31250",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457053/100/0/threaded",
          "name" : "20070116 MS07-004 VML Integer Overflow Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457164/100/0/threaded",
          "name" : "20070117 Re: MS07-004 VML Integer Overflow Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457274/100/0/threaded",
          "name" : "HPSBST02184",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21930",
          "name" : "21930",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-009A.html",
          "name" : "TA07-009A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0105",
          "name" : "ADV-2007-0105",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0129",
          "name" : "ADV-2007-0129",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-004",
          "name" : "MS07-004",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31287",
          "name" : "ie-vml-record-bo(31287)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1058",
          "name" : "oval:org.mitre.oval:def:1058",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the \"VML Buffer Overrun Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:sp4:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:64-bit:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0025",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "visual_studio_.net",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp_sp2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24150",
          "name" : "24150",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/932041",
          "name" : "VU#932041",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31887",
          "name" : "31887",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22476",
          "name" : "22476",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017638",
          "name" : "1017638",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
          "name" : "TA07-044A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0581",
          "name" : "ADV-2007-0581",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-012",
          "name" : "MS07-012",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A157",
          "name" : "oval:org.mitre.oval:def:157",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visual_studio_.net:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visual_studio_.net:2000:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visual_studio_.net:2003:gold:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:2000:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:xp_sp2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-13T20:28Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0026",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "sp1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24147",
          "name" : "24147",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/497756",
          "name" : "VU#497756",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31885",
          "name" : "31885",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22483",
          "name" : "22483",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017637",
          "name" : "1017637",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
          "name" : "TA07-044A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0580",
          "name" : "ADV-2007-0580",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-011",
          "name" : "MS07-011",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A540",
          "name" : "oval:org.mitre.oval:def:540",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-13T20:28Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0027",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1017487",
          "name" : "1017487",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/749964",
          "name" : "VU#749964",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31255",
          "name" : "31255",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457274/100/0/threaded",
          "name" : "HPSBST02184",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21856",
          "name" : "21856",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-009A.html",
          "name" : "TA07-009A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0103",
          "name" : "ADV-2007-0103",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-002",
          "name" : "MS07-002",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A119",
          "name" : "oval:org.mitre.oval:def:119",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:v.x:*:mac:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0028",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23676",
          "name" : "23676",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017485",
          "name" : "1017485",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html",
          "name" : "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.fortinet.com/FortiGuardCenter/advisory/FGA-2007-01.html",
          "name" : "http://www.fortinet.com/FortiGuardCenter/advisory/FGA-2007-01.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/493185",
          "name" : "VU#493185",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31249",
          "name" : "31249",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457274/100/0/threaded",
          "name" : "HPSBST02184",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21952",
          "name" : "21952",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-009A.html",
          "name" : "TA07-009A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0103",
          "name" : "ADV-2007-0103",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-002",
          "name" : "MS07-002",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A768",
          "name" : "oval:org.mitre.oval:def:768",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an \"Improper Memory Access Vulnerability.\"  NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:v.x:*:mac:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0029",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1017487",
          "name" : "1017487",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/31256",
          "name" : "31256",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457274/100/0/threaded",
          "name" : "HPSBST02184",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21877",
          "name" : "21877",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-009A.html",
          "name" : "TA07-009A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0103",
          "name" : "ADV-2007-0103",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-002",
          "name" : "MS07-002",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1102",
          "name" : "oval:org.mitre.oval:def:1102",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka \"Excel Malformed String Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:v.x:*:mac:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0030",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=460",
          "name" : "20070109 Microsoft Excel Invalid Column Heap Corruption Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017487",
          "name" : "1017487",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/302836",
          "name" : "VU#302836",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31257",
          "name" : "31257",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457274/100/0/threaded",
          "name" : "HPSBST02184",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21925",
          "name" : "21925",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-009A.html",
          "name" : "TA07-009A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0103",
          "name" : "ADV-2007-0103",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-002",
          "name" : "MS07-002",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A323",
          "name" : "oval:org.mitre.oval:def:323",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:v.x:*:mac:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0031",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=461",
          "name" : "20070109 Microsoft Excel Long Palette Heap Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017487",
          "name" : "1017487",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/625532",
          "name" : "VU#625532",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31258",
          "name" : "31258",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457274/100/0/threaded",
          "name" : "HPSBST02184",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21922",
          "name" : "21922",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-009A.html",
          "name" : "TA07-009A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0103",
          "name" : "ADV-2007-0103",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-002",
          "name" : "MS07-002",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A753",
          "name" : "oval:org.mitre.oval:def:753",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:v.x:*:mac:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0032",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0033",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "outlook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23674",
          "name" : "23674",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017488",
          "name" : "1017488",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/476900",
          "name" : "VU#476900",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31252",
          "name" : "31252",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457274/100/0/threaded",
          "name" : "HPSBST02184",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21931",
          "name" : "21931",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-009A.html",
          "name" : "TA07-009A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0104",
          "name" : "ADV-2007-0104",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-003",
          "name" : "MS07-003",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A516",
          "name" : "oval:org.mitre.oval:def:516",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook:2000:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook:2002:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook:2003:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0034",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "outlook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23674",
          "name" : "23674",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017488",
          "name" : "1017488",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.computerterrorism.com/research/ct09-01-2007.htm",
          "name" : "http://www.computerterrorism.com/research/ct09-01-2007.htm",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/271860",
          "name" : "VU#271860",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31254",
          "name" : "31254",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456589/100/0/threaded",
          "name" : "20070111 Computer Terrorism (UK) :: Incident Response Centre - Microsoft Outlook Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457274/100/0/threaded",
          "name" : "HPSBST02184",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21936",
          "name" : "21936",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-009A.html",
          "name" : "TA07-009A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0104",
          "name" : "ADV-2007-0104",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-003",
          "name" : "MS07-003",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A153",
          "name" : "oval:org.mitre.oval:def:153",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka \"Microsoft Outlook Advanced Find Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook:2000:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook:2002:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook:2003:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0035",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.kb.cert.org/vuls/id/260777",
          "name" : "VU#260777",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/34387",
          "name" : "34387",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23804",
          "name" : "23804",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018013",
          "name" : "1018013",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1709",
          "name" : "ADV-2007-1709",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-024",
          "name" : "MS07-024",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1737",
          "name" : "oval:org.mitre.oval:def:1737",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the \"Word Array Overflow Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2006:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-05-08T22:19Z",
    "lastModifiedDate" : "2018-10-30T16:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0036",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0037",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0038",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "gold",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0470.html",
          "name" : "20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24659",
          "name" : "24659",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2542",
          "name" : "2542",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp",
          "name" : "http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/191609",
          "name" : "VU#191609",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/33629",
          "name" : "33629",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464269/100/0/threaded",
          "name" : "20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464339/100/0/threaded",
          "name" : "20070330 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464340/100/0/threaded",
          "name" : "20070331 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464342/100/0/threaded",
          "name" : "20070331 RE: [Full-disclosure] 0-day ANI vulnerability in Microsoft Windows(CVE-2007-0038)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464459/100/100/threaded",
          "name" : "20070402 More information on ZERT patch for ANI 0day",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464460/100/100/threaded",
          "name" : "20070402 MS announces out-of-band patch for ANI 0day",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/466186/100/200/threaded",
          "name" : "HPSBST02206",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-089A.html",
          "name" : "TA07-089A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-093A.html",
          "name" : "TA07-093A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-100A.html",
          "name" : "TA07-100A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1215",
          "name" : "ADV-2007-1215",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-017",
          "name" : "MS07-017",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33301",
          "name" : "win-ani-code-execution(33301)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1854",
          "name" : "oval:org.mitre.oval:def:1854",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:gold:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:gold:*:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:gold:*:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:gold:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:gold:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional_x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-30T20:19Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0039",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "exchange_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-476"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063232.html",
          "name" : "20070509 Exchange Calendar MODPROPS Denial of Service (CVE-2007-0039)",
          "refsource" : "FULLDISC",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25183",
          "name" : "25183",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.determina.com/security.research/vulnerabilities/exchange-ical-modprops.html",
          "name" : "http://www.determina.com/security.research/vulnerabilities/exchange-ical-modprops.html",
          "refsource" : "MISC",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.osvdb.org/34390",
          "name" : "34390",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468047/100/0/threaded",
          "name" : "20070508 Exchange Calendar MODPROPS Denial of Service (CVE-2007-0039)",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23808",
          "name" : "23808",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018015",
          "name" : "1018015",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1711",
          "name" : "ADV-2007-1711",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026",
          "name" : "MS07-026",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33888",
          "name" : "exchange-ical-dos(33888)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1593",
          "name" : "oval:org.mitre.oval:def:1593",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2007:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-08T23:19Z",
    "lastModifiedDate" : "2020-04-09T13:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0040",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html",
          "name" : "SSRT071446",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35960",
          "name" : "35960",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26002",
          "name" : "26002",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.iss.net/threats/267.html",
          "name" : "20070710 Microsoft Windows Active Directory Remote Code Execution",
          "refsource" : "ISS",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/487905",
          "name" : "VU#487905",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24800",
          "name" : "24800",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018355",
          "name" : "1018355",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-191A.html",
          "name" : "TA07-191A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2481",
          "name" : "ADV-2007-2481",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-039",
          "name" : "MS07-039",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2012",
          "name" : "oval:org.mitre.oval:def:2012",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of \"convertible attributes.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-07-10T22:30Z",
    "lastModifiedDate" : "2019-04-30T14:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0041",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : ".net_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html",
          "name" : "SSRT071446",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35954",
          "name" : "35954",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26003",
          "name" : "26003",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24778",
          "name" : "24778",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018356",
          "name" : "1018356",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-191A.html",
          "name" : "TA07-191A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2482",
          "name" : "ADV-2007-2482",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040",
          "name" : "MS07-040",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34637",
          "name" : "ms-dotnet-pe-loader-bo(34637)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2093",
          "name" : "oval:org.mitre.oval:def:2093",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an \"unchecked buffer\" and unvalidated message lengths, probably a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:1.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:1.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:2.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-07-10T22:30Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0042",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : ".net_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html",
          "name" : "SSRT071446",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26003",
          "name" : "26003",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security-assessment.com/files/advisories/2007-07-11_Multiple_.NET_Null_Byte_Injection_Vulnerabilities.pdf",
          "name" : "http://security-assessment.com/files/advisories/2007-07-11_Multiple_.NET_Null_Byte_Injection_Vulnerabilities.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018356",
          "name" : "1018356",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-191A.html",
          "name" : "TA07-191A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2482",
          "name" : "ADV-2007-2482",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040",
          "name" : "MS07-040",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2070",
          "name" : "oval:org.mitre.oval:def:2070",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka \"Null Byte Termination Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:1.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:1.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:2.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-07-10T22:30Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0043",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : ".net_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html",
          "name" : "SSRT071446",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35956",
          "name" : "35956",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26003",
          "name" : "26003",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24811",
          "name" : "24811",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018356",
          "name" : "1018356",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-191A.html",
          "name" : "TA07-191A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2482",
          "name" : "ADV-2007-2482",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040",
          "name" : "MS07-040",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34639",
          "name" : "ms-dotnet-jit-bo(34639)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1873",
          "name" : "oval:org.mitre.oval:def:1873",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an \"unchecked buffer,\" probably a buffer overflow, aka \".NET JIT Compiler Vulnerability\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:1.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:1.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:2.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-07-10T22:30Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0044",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "acrobat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "acrobat_3d",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "acrobat_reader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf",
          "name" : "http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html",
          "name" : "SUSE-SA:2007:011",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23812",
          "name" : "23812",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23882",
          "name" : "23882",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29065",
          "name" : "29065",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200701-16.xml",
          "name" : "GLSA-200701-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2090",
          "name" : "2090",
          "refsource" : "SREASON",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017469",
          "name" : "1017469",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0144.html",
          "name" : "RHSA-2008:0144",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455801/100/0/threaded",
          "name" : "20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21858",
          "name" : "21858",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0032",
          "name" : "ADV-2007-0032",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.wisec.it/vulns.php?page=9",
          "name" : "http://www.wisec.it/vulns.php?page=9",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31266",
          "name" : "adobe-acrobat-pdf-csrf(31266)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10042",
          "name" : "oval:org.mitre.oval:def:10042",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka \"Universal CSRF and session riding.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.1:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.1:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.2:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.2:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.3:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.3:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.4:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.4:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.5:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.5:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.6:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.6:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.7:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.7:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:*:*:elements:*:*:*:*:*",
          "versionEndIncluding" : "7.0.8"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.8:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.8:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_3d:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-03T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0045",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "acrobat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "acrobat_3d",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "acrobat_reader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf",
          "name" : "http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html",
          "name" : "http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742",
          "name" : "HPSBUX02153",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html",
          "name" : "SUSE-SA:2007:011",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23483",
          "name" : "23483",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23691",
          "name" : "23691",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23812",
          "name" : "23812",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23877",
          "name" : "23877",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23882",
          "name" : "23882",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24457",
          "name" : "24457",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24533",
          "name" : "24533",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/33754",
          "name" : "33754",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200701-16.xml",
          "name" : "GLSA-200701-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2090",
          "name" : "2090",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017469",
          "name" : "1017469",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1023007",
          "name" : "1023007",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131",
          "name" : "SSA:2007-066-05",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1",
          "name" : "102847",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/advisories/apsa07-01.html",
          "name" : "http://www.adobe.com/support/security/advisories/apsa07-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.adobe.com/support/security/advisories/apsa07-02.html",
          "name" : "http://www.adobe.com/support/security/advisories/apsa07-02.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb07-01.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb07-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb09-15.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb09-15.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.disenchant.ch/blog/hacking-with-browser-plugins/34",
          "name" : "http://www.disenchant.ch/blog/hacking-with-browser-plugins/34",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.gnucitizen.org/blog/danger-danger-danger/",
          "name" : "http://www.gnucitizen.org/blog/danger-danger-danger/",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gnucitizen.org/blog/universal-pdf-xss-after-party",
          "name" : "http://www.gnucitizen.org/blog/universal-pdf-xss-after-party",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/815960",
          "name" : "VU#815960",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2007/mfsa2007-02.html",
          "name" : "http://www.mozilla.org/security/announce/2007/mfsa2007-02.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0021.html",
          "name" : "RHSA-2007:0021",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455790/100/0/threaded",
          "name" : "20070103 Universal XSS with PDF files: highly dangerous",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455800/100/0/threaded",
          "name" : "20070103 Re: Universal XSS with PDF files: highly dangerous",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455801/100/0/threaded",
          "name" : "20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455831/100/0/threaded",
          "name" : "20070103 Re: [WEB SECURITY] Universal XSS with PDF files: highly dangerous",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455836/100/0/threaded",
          "name" : "20070103 RE: [WEB SECURITY] Universal XSS with PDF files: highly dangerous",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455906/100/0/threaded",
          "name" : "20070104 Universal PDF XSS After Party",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21858",
          "name" : "21858",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA09-286B.html",
          "name" : "TA09-286B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0032",
          "name" : "ADV-2007-0032",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0957",
          "name" : "ADV-2007-0957",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/2898",
          "name" : "ADV-2009-2898",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.wisec.it/vulns.php?page=9",
          "name" : "http://www.wisec.it/vulns.php?page=9",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31271",
          "name" : "adobe-acrobat-pdf-xss(31271)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6487",
          "name" : "oval:org.mitre.oval:def:6487",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9693",
          "name" : "oval:org.mitre.oval:def:9693",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://rhn.redhat.com/errata/RHSA-2007-0017.html",
          "name" : "RHSA-2007:0017",
          "refsource" : "REDHAT",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka \"Universal XSS (UXSS).\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.1:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.1:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.2:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.2:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.3:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.3:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.4:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.4:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.5:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.5:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.6:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.6:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.7:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.7:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:*:*:elements:*:*:*:*:*",
          "versionEndIncluding" : "7.0.8"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.8:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.8:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_3d:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-03T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0046",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "acrobat_reader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf",
          "name" : "http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html",
          "name" : "SUSE-SA:2007:011",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23691",
          "name" : "23691",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23812",
          "name" : "23812",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23877",
          "name" : "23877",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23882",
          "name" : "23882",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24533",
          "name" : "24533",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200701-16.xml",
          "name" : "GLSA-200701-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2090",
          "name" : "2090",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017469",
          "name" : "1017469",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1",
          "name" : "102847",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb07-01.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb07-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0021.html",
          "name" : "RHSA-2007:0021",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455801/100/0/threaded",
          "name" : "20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0032",
          "name" : "ADV-2007-0032",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0957",
          "name" : "ADV-2007-0957",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.wisec.it/vulns.php?page=9",
          "name" : "http://www.wisec.it/vulns.php?page=9",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31272",
          "name" : "adobe-acrobat-msvcrt-code-execution(31272)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9684",
          "name" : "oval:org.mitre.oval:def:9684",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://rhn.redhat.com/errata/RHSA-2007-0017.html",
          "name" : "RHSA-2007:0017",
          "refsource" : "REDHAT",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-03T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0047",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "acrobat_reader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf",
          "name" : "http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html",
          "name" : "SUSE-SA:2007:011",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23882",
          "name" : "23882",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017469",
          "name" : "1017469",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0032",
          "name" : "ADV-2007-0032",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31291",
          "name" : "adobe-acrobat-xmlhttp-response-splitting(31291)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CRLF injection vulnerability in Adobe Acrobat Reader Plugin before 8.0.0, when used with the Microsoft.XMLHTTP ActiveX object in Internet Explorer, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the javascript: URI in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-03T21:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0048",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "acrobat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "acrobat_3d",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "acrobat_reader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf",
          "name" : "http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html",
          "name" : "http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html",
          "name" : "SUSE-SA:2007:011",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31596",
          "name" : "31596",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23812",
          "name" : "23812",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23882",
          "name" : "23882",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/33754",
          "name" : "33754",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200701-16.xml",
          "name" : "GLSA-200701-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2090",
          "name" : "2090",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017469",
          "name" : "1017469",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1023007",
          "name" : "1023007",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb07-01.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb07-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb09-15.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb09-15.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455801/100/0/threaded",
          "name" : "20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA09-286B.html",
          "name" : "TA09-286B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0032",
          "name" : "ADV-2007-0032",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/2898",
          "name" : "ADV-2009-2898",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.wisec.it/vulns.php?page=9",
          "name" : "http://www.wisec.it/vulns.php?page=9",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31273",
          "name" : "adobe-acrobat-character-dos(31273)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6348",
          "name" : "oval:org.mitre.oval:def:6348",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to a \"cross-site scripting issue.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.1:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.1:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.2:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.2:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.3:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.3:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.4:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.4:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.5:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.5:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.6:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.6:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.7:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.7:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:*:*:elements:*:*:*:*:*",
          "versionEndIncluding" : "7.0.8"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.8:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.8:*:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_3d:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-03T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0049",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "geckovich",
            "product" : {
              "product_data" : [ {
                "product_name" : "tasktracker",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "tasktracker_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31682",
          "name" : "31682",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23564",
          "name" : "23564",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21847",
          "name" : "21847",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31235",
          "name" : "tasktrackerpro-customize-auth-bypass(31235)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3068",
          "name" : "3068",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add action with a modified GroupID in a direct request to Customize.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geckovich:tasktracker:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geckovich:tasktracker_pro:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-04T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0050",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openpinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "openpinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2007-01/0176.html",
          "name" : "20070106 Re: OpenPinboard <= Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33375",
          "name" : "33375",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455795/100/0/threaded",
          "name" : "20070103 OpenPinboard <= Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455818/100/0/threaded",
          "name" : "20070103 Re: OpenPinboard <= Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  PHP remote file inclusion vulnerability in index.php in OpenPinboard 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the language parameter.  NOTE: this issue has been disputed by the developer and a third party, since the variable is set before use. CVE analysis suggests that there is a small time window of risk before the installation is complete."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openpinboard:openpinboard:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-04T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0051",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "iphoto",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0100.html",
          "name" : "20070104 DMA[2007-0104a] - 'iLife iPhoto Photocasing Format String Vulnerability'",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=305215",
          "name" : "http://docs.info.apple.com/article.html?artnum=305215",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar//msg00003.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31165",
          "name" : "31165",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-04-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-04-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23615",
          "name" : "23615",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.digitalmunition.com/DMA[2007-0104a].txt",
          "name" : "http://www.digitalmunition.com/DMA[2007-0104a].txt",
          "refsource" : "MISC",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455968/100/0/threaded",
          "name" : "20070104 DMA[2007-0104a] - 'iLife iPhoto Photocasing Format String Vulnerability'",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21871",
          "name" : "21871",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0057",
          "name" : "ADV-2007-0057",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31281",
          "name" : "iphoto-xmltitle-format-string(31281)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3080",
          "name" : "3080",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:iphoto:6.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-04T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0052",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vizayn_haber",
            "product" : {
              "product_data" : [ {
                "product_name" : "vizayn_haber",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31518",
          "name" : "31518",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23576",
          "name" : "23576",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21836",
          "name" : "21836",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0015",
          "name" : "ADV-2007-0015",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31213",
          "name" : "vicayn-haberdetay-sql-injection(31213)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3061",
          "name" : "3061",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in haberdetay.asp in Vizayn Haber allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vizayn_haber:vizayn_haber:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-04T22:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0053",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "asp_siteware",
            "product" : {
              "product_data" : [ {
                "product_name" : "autodealer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32539",
          "name" : "32539",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23572",
          "name" : "23572",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21833",
          "name" : "21833",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0016",
          "name" : "ADV-2007-0016",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31219",
          "name" : "autodealer-detail-sql-injection(31219)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3062",
          "name" : "3062",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the iPro parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:asp_siteware:autodealer:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-04T22:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0054",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "belchior_foundry",
            "product" : {
              "product_data" : [ {
                "product_name" : "vcard_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33359",
          "name" : "33359",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455615/100/0/threaded",
          "name" : "20070101 vBulletin vCard PRO XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21844",
          "name" : "21844",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31182",
          "name" : "vcard-gbrowse-xss(31182)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior Foundry vCard PRO allows remote attackers to inject arbitrary web script or HTML via the sortby parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:belchior_foundry:vcard_pro:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-04T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0055",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fersch",
            "product" : {
              "product_data" : [ {
                "product_name" : "formbankserver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32545",
          "name" : "32545",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23539",
          "name" : "23539",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0012",
          "name" : "ADV-2007-0012",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31214",
          "name" : "formbankserver-name-directory-traversal(31214)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3063",
          "name" : "3063",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in formbankcgi.exe/AbfrageForm in Formbankserver 1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the Name parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fersch:formbankserver:1.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-04T22:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0056",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ashopsoftware",
            "product" : {
              "product_data" : [ {
                "product_name" : "ashop_administration_panel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ashop_deluxe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32553",
          "name" : "32553",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32554",
          "name" : "32554",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32555",
          "name" : "32555",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32556",
          "name" : "32556",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32557",
          "name" : "32557",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32558",
          "name" : "32558",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23547",
          "name" : "23547",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2091",
          "name" : "2091",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455629/100/0/threaded",
          "name" : "20070101 AShop Shopping Cart Multiple XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21845",
          "name" : "21845",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0028",
          "name" : "ADV-2007-0028",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31178",
          "name" : "ashop-multiple-scripts-xss(31178)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ashopsoftware:ashop_administration_panel:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ashopsoftware:ashop_deluxe:4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-04T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0057",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "network_admission_control_manager_and_server_system_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-255"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32578",
          "name" : "32578",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/23617",
          "name" : "23617",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017465",
          "name" : "1017465",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml",
          "name" : "20070103 Multiple Vulnerabilities in Cisco Clean Access",
          "refsource" : "CISCO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0030",
          "name" : "ADV-2007-0030",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:network_admission_control_manager_and_server_system_software:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.6.0.0",
          "versionEndIncluding" : "3.6.4.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:network_admission_control_manager_and_server_system_software:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "4.0.0.0",
          "versionEndExcluding" : "4.0.3.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-04T22:28Z",
    "lastModifiedDate" : "2018-11-01T16:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0058",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "network_admission_control_manager_and_server_system_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23556",
          "name" : "23556",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017465",
          "name" : "1017465",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml",
          "name" : "20070103 Multiple Vulnerabilities in Cisco Clean Access",
          "refsource" : "CISCO",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/32579",
          "name" : "32579",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0030",
          "name" : "ADV-2007-0030",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:network_admission_control_manager_and_server_system_software:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.5.0",
          "versionEndIncluding" : "3.5.9"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:network_admission_control_manager_and_server_system_software:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.6.0.0",
          "versionEndIncluding" : "3.6.1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-04T22:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0059",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305149",
          "name" : "http://docs.info.apple.com/article.html?artnum=305149",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html",
          "name" : "APPLE-SA-2007-03-05",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31164",
          "name" : "31164",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-03-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-03-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.gnucitizen.org/blog/backdooring-quicktime-movies/",
          "name" : "http://www.gnucitizen.org/blog/backdooring-quicktime-movies/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/304064",
          "name" : "VU#304064",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.1.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-05T00:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0060",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ca",
            "product" : {
              "product_data" : [ {
                "product_name" : "advantage_data_transport",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "brightstor_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "brightstor_san_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cleverpath_aion",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cleverpath_ecm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cleverpath_olap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cleverpath_predictive_analysis_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "etrust_admin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_application_performance_monitor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_asset_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_data_transport_option",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_enterprise_job_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_jasmine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_network_and_systems_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_nsm_wireless_network_management_option",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_remote_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_service_level_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_software_delivery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_tng",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/26190",
          "name" : "26190",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.asp",
          "name" : "http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.asp",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809",
          "name" : "http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.iss.net/threats/272.html",
          "name" : "20070724 CA Message Queuing Server (Cam.exe) Overflow",
          "refsource" : "ISS",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/474602/100/0/threaded",
          "name" : "20070725 [CAID 35527]: CA Message Queuing (CAM / CAFT) Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25051",
          "name" : "25051",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018449",
          "name" : "1018449",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2638",
          "name" : "ADV-2007-2638",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32234",
          "name" : "systems-management-bo(32234)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:advantage_data_transport:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_portal:11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_san_manager:11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_san_manager:11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:cleverpath_aion:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:cleverpath_ecm:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:cleverpath_olap:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:cleverpath_predictive_analysis_server:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:cleverpath_predictive_analysis_server:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:etrust_admin:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:etrust_admin:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:etrust_admin:2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:etrust_admin:2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:etrust_admin:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:etrust_admin:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_application_performance_monitor:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_application_performance_monitor:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_asset_management:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_asset_management:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_asset_management:3.2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_asset_management:3.2:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_asset_management:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_asset_management:4.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_data_transport_option:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_enterprise_job_manager:1.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_enterprise_job_manager:1.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_jasmine:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_management:4.0:*:lotus_notes_domino:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_management:4.0:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_management:4.1:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_management:5.0:*:web_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_management:5.0.1:*:web_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_network_and_systems_management:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_network_and_systems_management:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_nsm_wireless_network_management_option:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_service_level_management:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_service_level_management:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_service_level_management:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_service_level_management:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_software_delivery:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_software_delivery:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_software_delivery:3.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_software_delivery:3.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_software_delivery:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_software_delivery:4.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_tng:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_tng:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_tng:2.2:*:*:ja:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_tng:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_tng:2.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-07-26T00:30Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0061",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vmware",
            "product" : {
              "product_data" : [ {
                "product_name" : "ace",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1_build_29996",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.0_build_13124",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1_build_19175",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3_build_34685",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3_build_42958",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4_build_44386",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "esx",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html",
          "name" : "20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26890",
          "name" : "26890",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/27694",
          "name" : "27694",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/27706",
          "name" : "27706",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200711-23.xml",
          "name" : "GLSA-200711-23",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.iss.net/threats/275.html",
          "name" : "20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities",
          "refsource" : "ISS",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25729",
          "name" : "25729",
          "refsource" : "BID",
          "tags" : [ "Patch", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018717",
          "name" : "1018717",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-543-1",
          "name" : "USN-543-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/ace/doc/releasenotes_ace.html",
          "name" : "http://www.vmware.com/support/ace/doc/releasenotes_ace.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html",
          "name" : "http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/player/doc/releasenotes_player.html",
          "name" : "http://www.vmware.com/support/player/doc/releasenotes_player.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/player2/doc/releasenotes_player2.html",
          "name" : "http://www.vmware.com/support/player2/doc/releasenotes_player2.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/server/doc/releasenotes_server.html",
          "name" : "http://www.vmware.com/support/server/doc/releasenotes_server.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html",
          "name" : "http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html",
          "name" : "http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/3229",
          "name" : "ADV-2007-3229",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33101",
          "name" : "dhcp-malformed-packet-bo(33101)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that triggers \"corrupt stack memory.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:ace:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.0",
          "versionEndExcluding" : "1.0.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:ace:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0",
          "versionEndExcluding" : "2.0.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.0",
          "versionEndExcluding" : "1.0.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0",
          "versionEndExcluding" : "2.0.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:server:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.0",
          "versionEndExcluding" : "1.0.4"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5",
          "versionEndExcluding" : "5.5.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "6.0",
          "versionEndExcluding" : "6.0.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:2.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:2.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:3.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-09-21T19:17Z",
    "lastModifiedDate" : "2019-07-16T12:20Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0062",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vmware",
            "product" : {
              "product_data" : [ {
                "product_name" : "ace",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vmware_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.0_build_13124",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1_build_19175",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3_build_34685",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3_build_42958",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4_build_44386",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          }, {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=227135",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=227135",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html",
          "name" : "20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html",
          "name" : "SUSE-SR:2009:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26890",
          "name" : "26890",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/27694",
          "name" : "27694",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/27706",
          "name" : "27706",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31396",
          "name" : "31396",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/34263",
          "name" : "34263",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200711-23.xml",
          "name" : "GLSA-200711-23",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200808-05.xml",
          "name" : "GLSA-200808-05",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.rpath.com/Advisories:rPSA-2009-0041",
          "name" : "http://wiki.rpath.com/Advisories:rPSA-2009-0041",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.iss.net/threats/275.html",
          "name" : "20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities",
          "refsource" : "ISS",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2009:153",
          "name" : "MDVSA-2009:153",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/501759/100/0/threaded",
          "name" : "20090312 rPSA-2009-0041-1 dhclient dhcp libdhcp4client",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25729",
          "name" : "25729",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018717",
          "name" : "1018717",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-543-1",
          "name" : "USN-543-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/support/ace/doc/releasenotes_ace.html",
          "name" : "http://www.vmware.com/support/ace/doc/releasenotes_ace.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html",
          "name" : "http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vmware.com/support/player/doc/releasenotes_player.html",
          "name" : "http://www.vmware.com/support/player/doc/releasenotes_player.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vmware.com/support/player2/doc/releasenotes_player2.html",
          "name" : "http://www.vmware.com/support/player2/doc/releasenotes_player2.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vmware.com/support/server/doc/releasenotes_server.html",
          "name" : "http://www.vmware.com/support/server/doc/releasenotes_server.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html",
          "name" : "http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html",
          "name" : "http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/3229",
          "name" : "ADV-2007-3229",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=339561",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=339561",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33102",
          "name" : "dhcp-param-overflow(33102)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:ace:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:ace:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:server:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:vmware_workstation:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:4.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.0_build_13124:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.1_build_19175:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.3_build_34685:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.3_build_42958:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.4_build_44386:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-09-21T19:17Z",
    "lastModifiedDate" : "2018-10-16T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0063",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vmware",
            "product" : {
              "product_data" : [ {
                "product_name" : "ace",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1_build_29996",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.0_build_13124",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1_build_19175",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3_build_34685",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3_build_42958",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4_build_44386",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "esx",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-191"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html",
          "name" : "20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26890",
          "name" : "26890",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/27694",
          "name" : "27694",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/27706",
          "name" : "27706",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200711-23.xml",
          "name" : "GLSA-200711-23",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.iss.net/threats/275.html",
          "name" : "20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities",
          "refsource" : "ISS",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25729",
          "name" : "25729",
          "refsource" : "BID",
          "tags" : [ "Patch", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018717",
          "name" : "1018717",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-543-1",
          "name" : "USN-543-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/ace/doc/releasenotes_ace.html",
          "name" : "http://www.vmware.com/support/ace/doc/releasenotes_ace.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html",
          "name" : "http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/player/doc/releasenotes_player.html",
          "name" : "http://www.vmware.com/support/player/doc/releasenotes_player.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/player2/doc/releasenotes_player2.html",
          "name" : "http://www.vmware.com/support/player2/doc/releasenotes_player2.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/server/doc/releasenotes_server.html",
          "name" : "http://www.vmware.com/support/server/doc/releasenotes_server.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html",
          "name" : "http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html",
          "name" : "http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/3229",
          "name" : "ADV-2007-3229",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33103",
          "name" : "dhcp-param-underflow(33103)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:ace:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.0",
          "versionEndExcluding" : "1.0.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:ace:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0",
          "versionEndExcluding" : "2.0.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.0",
          "versionEndExcluding" : "1.0.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0",
          "versionEndExcluding" : "2.0.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:server:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.0",
          "versionEndExcluding" : "1.0.4"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5",
          "versionEndExcluding" : "5.5.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "6.0",
          "versionEndExcluding" : "6.0.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:2.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:2.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:vmware:esx:3.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-09-21T19:17Z",
    "lastModifiedDate" : "2019-07-16T12:20Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0064",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_media_format_runtime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_media_services",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/28034",
          "name" : "28034",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/319385",
          "name" : "VU#319385",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485268/100/0/threaded",
          "name" : "SSRT071506",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/26776",
          "name" : "26776",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019074",
          "name" : "1019074",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-345A.html",
          "name" : "TA07-345A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/4183",
          "name" : "ADV-2007-4183",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-068",
          "name" : "MS07-068",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3622",
          "name" : "oval:org.mitre.oval:def:3622",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:windows_media_format_runtime:7.1:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:windows_media_format_runtime:9:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:windows_media_format_runtime:9.5:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:windows_media_format_runtime:9.5:*:x64:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:windows_media_format_runtime:11:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:windows_media_services:9.1:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-12-12T00:46Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0065",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "visual_basic",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28902",
          "name" : "28902",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27661",
          "name" : "27661",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019373",
          "name" : "1019373",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0510/references",
          "name" : "ADV-2008-0510",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-008",
          "name" : "MS08-008",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5388",
          "name" : "oval:org.mitre.oval:def:5388",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:office:*:*:mac\\+os:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:visual_basic:6.0:sp6:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-02-12T23:00Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0066",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "home_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "small_business_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2003",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-2-the-case-of-the-moderate-icmp-mitigations.aspx",
          "name" : "http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-2-the-case-of-the-moderate-icmp-mitigations.aspx",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28297",
          "name" : "28297",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019166",
          "name" : "1019166",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.iss.net/threats/282.html",
          "name" : "20070108 Multiple (3) Microsoft Windows TCP/IP Remote Code Execution and DoS Vulnerabilities",
          "refsource" : "ISS",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486317/100/0/threaded",
          "name" : "SSRT080003",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27139",
          "name" : "27139",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-008A.html",
          "name" : "TA08-008A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0069",
          "name" : "ADV-2008-0069",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-001",
          "name" : "MS08-001",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39254",
          "name" : "win-tcpip-icmp-dos(39254)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5271",
          "name" : "oval:org.mitre.oval:def:5271",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka \"Windows Kernel TCP/IP/ICMP Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:home_server:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:small_business_server:2003:*:sp1:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:gold:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:sp1:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T20:46Z",
    "lastModifiedDate" : "2019-02-26T14:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0067",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_domino_web_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2_cf2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35766",
          "name" : "35766",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25542",
          "name" : "25542",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24307",
          "name" : "24307",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018189",
          "name" : "1018189",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2046",
          "name" : "ADV-2007-2046",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg21257251",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg21257251",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34689",
          "name" : "domino-unspecified-dos(34689)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.0.2_cf2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.5.4:*:fp1:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.5.4:*:fp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.5.5:*:fp1:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:6.5.5:*:fp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_web_server:7.0.2:*:fp1:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-06-06T10:30Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0068",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35765",
          "name" : "35765",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25520",
          "name" : "25520",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24322",
          "name" : "24322",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2063",
          "name" : "ADV-2007-2063",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg21258784",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg21258784",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34718",
          "name" : "domino-signature-privilege-escalation(34718)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:7.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-06-06T21:30Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0069",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx",
          "name" : "http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28297",
          "name" : "28297",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1019166",
          "name" : "1019166",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.iss.net/threats/282.html",
          "name" : "20070108 Multiple (3) Microsoft Windows TCP/IP Remote Code Execution and DoS Vulnerabilities",
          "refsource" : "ISS",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/115083",
          "name" : "VU#115083",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/486317/100/0/threaded",
          "name" : "SSRT080003",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27100",
          "name" : "27100",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-008A.html",
          "name" : "TA08-008A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0069",
          "name" : "ADV-2008-0069",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-001",
          "name" : "MS08-001",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39452",
          "name" : "win-ssm-igmp-bo(39452)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39453",
          "name" : "win-ssm-mld-bo(39453)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5370",
          "name" : "oval:org.mitre.oval:def:5370",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka \"Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-01-08T20:46Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0071",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "flash_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.22.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.24.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.33.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.34.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.35.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.39.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.16.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.18d60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.20.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.28.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.31.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.45.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.47.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.48.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.112.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.114.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.115.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html",
          "name" : "http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf",
          "name" : "http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf",
          "refsource" : "MISC",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://isc.sans.org/diary.html?storyid=4465",
          "name" : "http://isc.sans.org/diary.html?storyid=4465",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008//May/msg00001.html",
          "name" : "APPLE-SA-2008-05-28",
          "refsource" : "APPLE",
          "tags" : [ "Mailing List" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html",
          "name" : "SUSE-SA:2008:022",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29763",
          "name" : "29763",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29865",
          "name" : "29865",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30404",
          "name" : "30404",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30430",
          "name" : "30430",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30507",
          "name" : "30507",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1",
          "name" : "238305",
          "refsource" : "SUNALERT",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb08-11.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb08-11.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml",
          "name" : "GLSA-200804-21",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.iss.net/threats/289.html",
          "name" : "20080408 Adobe Flash Player Invalid Pointer Vulnerability",
          "refsource" : "ISS",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/159523",
          "name" : "VU#159523",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/395473",
          "name" : "VU#395473",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/",
          "name" : "http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/44282",
          "name" : "44282",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0221.html",
          "name" : "RHSA-2008:0221",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28695",
          "name" : "28695",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/29386",
          "name" : "29386",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019811",
          "name" : "1019811",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020114",
          "name" : "1020114",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-100A.html",
          "name" : "TA08-100A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-149A.html",
          "name" : "TA08-149A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-150A.html",
          "name" : "TA08-150A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1662/references",
          "name" : "ADV-2008-1662",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1697",
          "name" : "ADV-2008-1697",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1724/references",
          "name" : "ADV-2008-1724",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-08-032/",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-08-032/",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/37277",
          "name" : "multimedia-file-integer-overflow(37277)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10379",
          "name" : "oval:org.mitre.oval:def:10379",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "8.0",
          "versionEndIncluding" : "8.0.39.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "9.0",
          "versionEndIncluding" : "9.0.115.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-04-09T21:05Z",
    "lastModifiedDate" : "2018-10-30T16:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0072",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trend_micro",
            "product" : {
              "product_data" : [ {
                "product_name" : "serverprotect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.58",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.iss.net/archive/trend.html",
          "name" : "http://blogs.iss.net/archive/trend.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32618",
          "name" : "32618",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.iss.net/threats/309.html",
          "name" : "20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)",
          "refsource" : "ISS",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/768681",
          "name" : "VU#768681",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/32261",
          "name" : "32261",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/3127",
          "name" : "ADV-2008-3127",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/38760",
          "name" : "application-rpc-read-bo(38760)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a read operation over RPC."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.58:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-11-17T23:30Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0073",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trend_micro",
            "product" : {
              "product_data" : [ {
                "product_name" : "serverprotect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.58",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.iss.net/archive/trend.html",
          "name" : "http://blogs.iss.net/archive/trend.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32618",
          "name" : "32618",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.iss.net/threats/309.html",
          "name" : "20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)",
          "refsource" : "ISS",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/768681",
          "name" : "VU#768681",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/32261",
          "name" : "32261",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/3127",
          "name" : "ADV-2008-3127",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39050",
          "name" : "application-rpc-file-read-bo(39050)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a file read operation over RPC."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.58:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-11-17T23:30Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0074",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trend_micro",
            "product" : {
              "product_data" : [ {
                "product_name" : "serverprotect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.58",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.iss.net/archive/trend.html",
          "name" : "http://blogs.iss.net/archive/trend.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/32618",
          "name" : "32618",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.iss.net/threats/309.html",
          "name" : "20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)",
          "refsource" : "ISS",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/768681",
          "name" : "VU#768681",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/32261",
          "name" : "32261",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/3127",
          "name" : "ADV-2008-3127",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39051",
          "name" : "application-rpc-folder-read-bo(39051)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a folder read operation over RPC."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.58:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2008-11-17T23:30Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0075",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aspbb",
            "product" : {
              "product_data" : [ {
                "product_name" : "aspbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33364",
          "name" : "33364",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2100",
          "name" : "2100",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.aria-security.com/forum/showthread.php?t=82",
          "name" : "http://www.aria-security.com/forum/showthread.php?t=82",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455683/100/0/threaded",
          "name" : "20070102 AspBB Remote Password Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31230",
          "name" : "aspbb-aspbb-info-disclosure(31230)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "AspBB stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for db/aspbb.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aspbb:aspbb:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0076",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "2enetworx",
            "product" : {
              "product_data" : [ {
                "product_name" : "openforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33366",
          "name" : "33366",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2099",
          "name" : "2099",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.aria-security.com/forum/showthread.php?t=80",
          "name" : "http://www.aria-security.com/forum/showthread.php?t=80",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455684/100/0/threaded",
          "name" : "20070102 Openforum Remote password Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31209",
          "name" : "openforum-openforum-password-disclosure(31209)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Openforum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for openforum.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:2enetworx:openforum:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0077",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "lblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33367",
          "name" : "33367",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2098",
          "name" : "2098",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017462",
          "name" : "1017462",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.aria-security.com/forum/showthread.php?t=79",
          "name" : "http://www.aria-security.com/forum/showthread.php?t=79",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455681/100/0/threaded",
          "name" : "20070102 lblog Remote Password Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31229",
          "name" : "lblog-newfolder-information-disclosure(31229)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "lblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a certain file in admin/db/newFolder/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lblog:lblog:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0078",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "battleblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "battleblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0d",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33360",
          "name" : "33360",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2097",
          "name" : "2097",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.aria-security.com/forum/showthread.php?t=76",
          "name" : "http://www.aria-security.com/forum/showthread.php?t=76",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455614/100/0/threaded",
          "name" : "20070101 BattleBlog Database Download Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31224",
          "name" : "battleblog-blankmaster-info-disclosure(31224)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BattleBlog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/blankmaster.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:battleblog:battleblog:1.0d:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0079",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "rblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32572",
          "name" : "32572",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23538",
          "name" : "23538",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2102",
          "name" : "2102",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.aria-security.com/forum/showthread.php?t=77",
          "name" : "http://www.aria-security.com/forum/showthread.php?t=77",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455626/100/0/threaded",
          "name" : "20070101 rblog Database Download Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31200",
          "name" : "rblog-database-info-disclosure(31200)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "rblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/admin.mdb or (2) data/rblog.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rblog:rblog:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0080",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freeradius",
            "product" : {
              "product_data" : [ {
                "product_name" : "freeradius",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32082",
          "name" : "32082",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017463",
          "name" : "1017463",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001304.html",
          "name" : "20070211 FreeRADIUS dispute of CVE-2007-0080",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.freeradius.org/security.html",
          "name" : "http://www.freeradius.org/security.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455678/100/0/threaded",
          "name" : "20070102 FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455812/100/0/threaded",
          "name" : "20070103 Re: FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31248",
          "name" : "freeradius-smbconnectserver-bo(31248)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance.  NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited \"only to local administrators who have write access to the server configuration files.\"  CVE concurs with the dispute."
        }, {
          "lang" : "en",
          "value" : "-- Official Vendor Statement from the FreeRADIUS Server project\r\n\r\nThis issue is not a security vulnerability.  The exploit is available only to local administrators who have write access to the server configuration files.  As such, this issue has no security impact on any system running FreeRADIUS.\r\n\r\n-- Official Vendor Statement from the FreeRADIUS Server project\r\n"
        }, {
          "lang" : "en",
          "value" : "A buffer overflow in the SMB_Connect_Server function in FreeRADIUS 1.1.4 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance.  This issue can not be exploited remotely, and can only be exploited by administrators who have write access to the server configuration files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeradius:freeradius:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 2.7,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0081",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sunbelt",
            "product" : {
              "product_data" : [ {
                "product_name" : "sunbelt_kerio_personal_firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.246",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.268",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2095",
          "name" : "2095",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.matousec.com/info/advisories/Kerio-Fake-iphlpapi-DLL-injection.php",
          "name" : "http://www.matousec.com/info/advisories/Kerio-Fake-iphlpapi-DLL-injection.php",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/33356",
          "name" : "33356",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455624/100/0/threaded",
          "name" : "20070101 Kerio Fake 'iphlpapi' DLL injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21828",
          "name" : "21828",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31232",
          "name" : "kerio-directory-code-execution(31232)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Sunbelt Kerio Personal Firewall (SKPF) 4.3.268 and 4.3.246, and possibly other versions allows local users to provide a Trojan horse iphlpapi.dll to SKPF by placing it in the installation directory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sunbelt:sunbelt_kerio_personal_firewall:4.3.246:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sunbelt:sunbelt_kerio_personal_firewall:4.3.268:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0082",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "imgallery",
            "product" : {
              "product_data" : [ {
                "product_name" : "imgallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/21827",
          "name" : "21827",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0010",
          "name" : "ADV-2007-0010",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31237",
          "name" : "imgallery-start1-file-upload(31237)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3049",
          "name" : "3049",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:imgallery:imgallery:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:imgallery:imgallery:2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0083",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nuked-klan",
            "product" : {
              "product_data" : [ {
                "product_name" : "nuked-klan",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_sp2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33368",
          "name" : "33368",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2101",
          "name" : "2101",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455726/100/0/threaded",
          "name" : "20070102 Nuked Klan <= 1.7 Remote Cookie Disclosure Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21850",
          "name" : "21850",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a getURL statement in a .swf file, as demonstrated by \"Remote Cookie Disclosure.\"  NOTE: it could be argued that this is an issue in Shockwave instead of Nuked Klan."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nuked-klan:nuked-klan:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nuked-klan:nuked-klan:1.2_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nuked-klan:nuked-klan:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nuked-klan:nuked-klan:1.3_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nuked-klan:nuked-klan:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nuked-klan:nuked-klan:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nuked-klan:nuked-klan:1.5_sp2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nuked-klan:nuked-klan:1.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0084",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "message_compiler",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.00.5239",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/37817",
          "name" : "37817",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455729/100/0/threaded",
          "name" : "20070102 Windows NT Message Compiler 1.00.5239 arbitrary code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455789/100/0/threaded",
          "name" : "20070103 Re: Windows NT Message Compiler 1.00.5239 arbitrary code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Buffer overflow in the Windows NT Message Compiler (MC) 1.00.5239 on Microsoft Windows XP allows local users to gain privileges via a long MC-filename.  NOTE: this issue has been disputed by a reliable third party who states that the compiler is not a privileged program, so privilege boundaries cannot be crossed."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:message_compiler:1.00.5239:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 2.7,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0085",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openbsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "openbsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://ilja.netric.org/files/Unusual%20bugs%2023c3.pdf",
          "name" : "http://ilja.netric.org/files/Unusual%20bugs%2023c3.pdf",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://marc.info/?l=openbsd-cvs&m=116781980706409&w=2",
          "name" : "[openbsd-cvs] 20070103 Re: CVS: cvs.openbsd.org: src",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=openbsd-cvs&m=116785923301416&w=2",
          "name" : "[openbsd-cvs] 20070103 CVS: cvs.openbsd.org: www",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23608",
          "name" : "23608",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017468",
          "name" : "1017468",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.openbsd.org/errata.html#agp",
          "name" : "[4.0] 007: SECURITY FIX: January 3, 2007",
          "refsource" : "OPENBSD",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.openbsd.org/errata39.html#agp",
          "name" : "[3.9] 017: SECURITY FIX: January 3, 2007",
          "refsource" : "OPENBSD",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/32574",
          "name" : "32574",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0043",
          "name" : "ADV-2007-0043",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31276",
          "name" : "openbsd-vga-privilege-escalation(31276)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when the kernel is compiled with the PCIAGP option and a non-AGP device is being used, allows local users to gain privileges via unspecified vectors, possibly related to agp_ioctl NULL pointer reference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:openbsd:openbsd:3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:openbsd:openbsd:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 1.5,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T11:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0086",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33456",
          "name" : "33456",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455833/100/0/threaded",
          "name" : "20070103 a cheesy Apache / IIS DoS vuln (+a question)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455879/100/0/threaded",
          "name" : "20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455882/100/0/threaded",
          "name" : "20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455920/100/0/threaded",
          "name" : "20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0087",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_information_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33457",
          "name" : "33457",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455833/100/0/threaded",
          "name" : "20070103 a cheesy Apache / IIS DoS vuln (+a question)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455879/100/0/threaded",
          "name" : "20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455882/100/0/threaded",
          "name" : "20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455920/100/0/threaded",
          "name" : "20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_information_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0088",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openmedia",
            "product" : {
              "product_data" : [ {
                "product_name" : "openmedia",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33370",
          "name" : "33370",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33371",
          "name" : "33371",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2103",
          "name" : "2103",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455786/100/0/threaded",
          "name" : "20070102 openmedia local read file",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31258",
          "name" : "openmedia-page-directory-traversal(31258)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in openmedia allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) src parameter to page.php or the (2) format parameter to search_form.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openmedia:openmedia:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0089",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jgbbs",
            "product" : {
              "product_data" : [ {
                "product_name" : "jgbbs",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aria-security.com/forum/showthread.php?t=87",
          "name" : "http://aria-security.com/forum/showthread.php?t=87",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33376",
          "name" : "33376",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455832/100/0/threaded",
          "name" : "20070103 jgbbs",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31274",
          "name" : "jgbbs-bbs-information-disclosure(31274)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "jgbbs stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/bbs.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jgbbs:jgbbs:3.0:beta_1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0090",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fermentigrafici",
            "product" : {
              "product_data" : [ {
                "product_name" : "wineglass",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aria-security.com/forum/showthread.php?p=112",
          "name" : "http://aria-security.com/forum/showthread.php?p=112",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/32575",
          "name" : "32575",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23594",
          "name" : "23594",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455807/100/0/threaded",
          "name" : "20070103 WineGlass \"data.mdb\" Remote Password Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0037",
          "name" : "ADV-2007-0037",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WineGlass stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/data.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fermentigrafici:wineglass:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0091",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "katy_whitton_web_development",
            "product" : {
              "product_data" : [ {
                "product_name" : "newscmslite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/37548",
          "name" : "37548",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31222",
          "name" : "newscmslite-newscms-info-disclosure(31222)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3066",
          "name" : "3066",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for newsCMS.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:katy_whitton_web_development:newscmslite:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0092",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "e-smart_cart",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-smart_cart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31679",
          "name" : "31679",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23610",
          "name" : "23610",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0036",
          "name" : "ADV-2007-0036",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31243",
          "name" : "esmartcart-productdetail-sql-injection(31243)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3074",
          "name" : "3074",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in productdetail.asp in E-SMARTCART 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-smart_cart:e-smart_cart:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0093",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cms-center",
            "product" : {
              "product_data" : [ {
                "product_name" : "simple_web_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://acid-root.new.fr/poc/18070102.txt",
          "name" : "http://acid-root.new.fr/poc/18070102.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/31657",
          "name" : "31657",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23590",
          "name" : "23590",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2106",
          "name" : "2106",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455814/100/0/threaded",
          "name" : "20070103 Simple Web Content Management System SQL Injection Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0040",
          "name" : "ADV-2007-0040",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31261",
          "name" : "swcms-page-sql-injection(31261)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3076",
          "name" : "3076",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cms-center:simple_web_cms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0094",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sven_moderow",
            "product" : {
              "product_data" : [ {
                "product_name" : "sven_moderow_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aria-security.com/forum/showthread.php?p=114",
          "name" : "http://aria-security.com/forum/showthread.php?p=114",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33363",
          "name" : "33363",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2105",
          "name" : "2105",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455788/100/0/threaded",
          "name" : "20070103 GuestBook v0.3a Remote Password Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31245",
          "name" : "guestbook-gbook-information-disclosure(31245)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sven_moderow:sven_moderow_guestbook:0.3a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0095",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpmyadmin",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpmyadmin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.9.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0034.html",
          "name" : "20070102 Inforamtion Discloser Vulnerabilities in \"phpMyAdmin\"",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051544.html",
          "name" : "20070102 Inforamtion Discloser Vulnerabilities in  phpMyAdmin",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33257",
          "name" : "33257",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2104",
          "name" : "2104",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:199",
          "name" : "MDKSA-2007:199",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31223",
          "name" : "phpmyadmin-darkblueorange-path-disclosure(31223)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "phpMyAdmin 2.9.1.1 allows remote attackers to obtain sensitive information via a direct request for themes/darkblue_orange/layout.inc.php, which reveals the path in an error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpmyadmin:phpmyadmin:2.9.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0096",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "carbon_communities",
            "product" : {
              "product_data" : [ {
                "product_name" : "carbon_communities",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4d",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aria-security.com/forum/showthread.php?t=85",
          "name" : "http://aria-security.com/forum/showthread.php?t=85",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/37549",
          "name" : "37549",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0038",
          "name" : "ADV-2007-0038",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31253",
          "name" : "carboncommunities-carbon2-info-disclosure(31253)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CarbonCommunities stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for DataBase/Carbon2.4d.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:carbon_communities:carbon_communities:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.4d"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0097",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "conexware",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerarchiver_2006",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.64.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=116791509125050&w=2",
          "name" : "20070104 [vuln.sg] PowerArchiver PAISO.DLL Buffer Overflow",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32576",
          "name" : "32576",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23559",
          "name" : "23559",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://vuln.sg/powarc964-en.html",
          "name" : "http://vuln.sg/powarc964-en.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455892/100/0/threaded",
          "name" : "20070104 [vuln.sg] PowerArchiver PAISO.DLL Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0041",
          "name" : "ADV-2007-0041",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31263",
          "name" : "powerarchiver-loadtree-readheader-bo(31263)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:conexware:powerarchiver_2006:9.64.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0098",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "verliadmin",
            "product" : {
              "product_data" : [ {
                "product_name" : "verliadmin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32352",
          "name" : "32352",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0035",
          "name" : "ADV-2007-0035",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31241",
          "name" : "verliadmin-language-file-include(31241)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3075",
          "name" : "3075",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:verliadmin:verliadmin:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-05T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0099",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "xml_core_services",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-362"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0113.html",
          "name" : "20070104 Re: Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://isc.sans.org/diary.php?storyid=2004",
          "name" : "http://isc.sans.org/diary.php?storyid=2004",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=122703006921213&w=2",
          "name" : "SSRT080164",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32627",
          "name" : "32627",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2007/Jan/0110.html",
          "name" : "20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23655",
          "name" : "23655",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1021164",
          "name" : "1021164",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455965/100/0/threaded",
          "name" : "20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455986/100/0/threaded",
          "name" : "20070104 RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456343/100/0/threaded",
          "name" : "20070104 Re: RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21872",
          "name" : "21872",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-316A.html",
          "name" : "TA08-316A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/3111",
          "name" : "ADV-2008-3111",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-069",
          "name" : "MS08-069",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5793",
          "name" : "oval:org.mitre.oval:def:5793",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka \"MSXML Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:xml_core_services:3.0:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-08T20:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0100",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "perforce",
            "product" : {
              "product_data" : [ {
                "product_name" : "perforce_client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33369",
          "name" : "33369",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455977/100/0/threaded",
          "name" : "20070104 Perforce client: security hole by design",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attackers to overwrite arbitrary files by modifying the client config file on the server, or by operating a malicious server."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:perforce:perforce_client:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-08T20:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0101",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spine",
            "product" : {
              "product_data" : [ {
                "product_name" : "spine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32577",
          "name" : "32577",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23537",
          "name" : "23537",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://spine.sourceforge.net/changelog.html",
          "name" : "http://spine.sourceforge.net/changelog.html",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0042",
          "name" : "ADV-2007-0042",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31283",
          "name" : "spine-unspecified-csrf(31283)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in SPINE allows remote attackers to perform unauthorized actions as administrators via unspecified vectors.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spine:spine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-08T20:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0102",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "preview",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31221",
          "name" : "31221",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-06-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-06-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21910",
          "name" : "21910",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017749",
          "name" : "1017749",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31364",
          "name" : "multiple-vendor-pdf-code-execution(31364)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:preview:3.0.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0103",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "acrobat_reader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-06-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-06-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21910",
          "name" : "21910",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017749",
          "name" : "1017749",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31364",
          "name" : "multiple-vendor-pdf-code-execution(31364)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0104",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xpdf",
            "product" : {
              "product_data" : [ {
                "product_name" : "xpdf",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1_pl1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1_pl2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0_pl2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "kde",
            "product" : {
              "product_data" : [ {
                "product_name" : "kde",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-06-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-06-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23791",
          "name" : "23791",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23799",
          "name" : "23799",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23808",
          "name" : "23808",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23813",
          "name" : "23813",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23815",
          "name" : "23815",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23839",
          "name" : "23839",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23844",
          "name" : "23844",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23876",
          "name" : "23876",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24204",
          "name" : "24204",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017514",
          "name" : "1017514",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.html",
          "name" : "http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kde.org/info/security/advisory-20070115-1.txt",
          "name" : "http://www.kde.org/info/security/advisory-20070115-1.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:018",
          "name" : "MDKSA-2007:018",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:019",
          "name" : "MDKSA-2007:019",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:020",
          "name" : "MDKSA-2007:020",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:021",
          "name" : "MDKSA-2007:021",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:022",
          "name" : "MDKSA-2007:022",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:024",
          "name" : "MDKSA-2007:024",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_3_sr.html",
          "name" : "SUSE-SR:2007:003",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457055/100/0/threaded",
          "name" : "20070116 [KDE Security Advisory] kpdf/kword/xpdf denial of service vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21910",
          "name" : "21910",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017749",
          "name" : "1017749",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-410-1",
          "name" : "USN-410-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-410-2",
          "name" : "USN-410-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0203",
          "name" : "ADV-2007-0203",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0212",
          "name" : "ADV-2007-0212",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0244",
          "name" : "ADV-2007-0244",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31364",
          "name" : "multiple-vendor-pdf-code-execution(31364)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-964",
          "name" : "https://issues.rpath.com/browse/RPL-964",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xpdf:xpdf:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xpdf:xpdf:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xpdf:xpdf:3.0.1_pl1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xpdf:xpdf:3.0.1_pl2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xpdf:xpdf:3.0_pl2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0105",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "secure_access_control_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23629",
          "name" : "23629",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017475",
          "name" : "1017475",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20070105-csacs.shtml",
          "name" : "20070105 Multiple Vulnerabilities in Cisco Secure Access Control Server",
          "refsource" : "CISCO",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/744249",
          "name" : "VU#744249",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/32642",
          "name" : "32642",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21900",
          "name" : "21900",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0068",
          "name" : "ADV-2007-0068",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31323",
          "name" : "cisco-acs-csadmin-bo(31323)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted HTTP GET request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:secure_access_control_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.0.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0106",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33397",
          "name" : "33397",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23595",
          "name" : "23595",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2114",
          "name" : "2114",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://wordpress.org/development/2007/01/wordpress-206/",
          "name" : "http://wordpress.org/development/2007/01/wordpress-206/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.hardened-php.net/advisory_012007.140.html",
          "name" : "http://www.hardened-php.net/advisory_012007.140.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456048/100/0/threaded",
          "name" : "20070105 Advisory 01/2007: WordPress CSRF Protection XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21893",
          "name" : "21893",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0061",
          "name" : "ADV-2007-0061",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token and quote characters or HTML tags in URL variable names, which are not properly handled when WordPress generates a new link to verify the request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0107",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31579",
          "name" : "31579",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23595",
          "name" : "23595",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23741",
          "name" : "23741",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200701-10.xml",
          "name" : "GLSA-200701-10",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2112",
          "name" : "2112",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://wordpress.org/development/2007/01/wordpress-206/",
          "name" : "http://wordpress.org/development/2007/01/wordpress-206/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.hardened-php.net/advisory_022007.141.html",
          "name" : "http://www.hardened-php.net/advisory_022007.141.html",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.005.html",
          "name" : "OpenPKG-SA-2007.005",
          "refsource" : "OPENPKG",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456049/100/0/threaded",
          "name" : "20070105 Advisory 02/2007: WordPress Trackback Charset Decoding SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21907",
          "name" : "21907",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0061",
          "name" : "ADV-2007-0061",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31297",
          "name" : "wordpress-mbstring-security-bypass(31297)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that the \"mbstring\" extension be enabled.\r\nThis vulnerability is addressed in the following product release:\r\nWordPress, WordPress, 2.0.6"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0108",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.91",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31358",
          "name" : "31358",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23619",
          "name" : "23619",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017471",
          "name" : "1017471",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974970.htm",
          "name" : "http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974970.htm",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21886",
          "name" : "21886",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0064",
          "name" : "ADV-2007-0064",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31343",
          "name" : "novell-profile-security-bypass(31343)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:client:4.91:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0109",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31577",
          "name" : "31577",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23621",
          "name" : "23621",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23741",
          "name" : "23741",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200701-10.xml",
          "name" : "GLSA-200701-10",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2113",
          "name" : "2113",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455927/100/0/threaded",
          "name" : "20070103 Wordpress <= 2.x dictionnary & Bruteforce attack",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0062",
          "name" : "ADV-2007-0062",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31262",
          "name" : "wordpress-account-enumeration(31262)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0110",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "access_manager_identity_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31359",
          "name" : "31359",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23654",
          "name" : "23654",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017483",
          "name" : "1017483",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21921",
          "name" : "21921",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0073",
          "name" : "ADV-2007-0073",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://secure-support.novell.com/KanisaPlatform/Publishing/143/3615264_f.SAL_Public.html",
          "name" : "https://secure-support.novell.com/KanisaPlatform/Publishing/143/3615264_f.SAL_Public.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject arbitrary web script or HTML via the IssueInstant parameter, which is not properly handled in the resulting error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:novell:access_manager_identity_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0111",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "resco",
            "product" : {
              "product_data" : [ {
                "product_name" : "photo_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blog.trendmicro.com/flaw-in-3rd-party-app-weakens-windows-mobile/",
          "name" : "http://blog.trendmicro.com/flaw-in-3rd-party-app-weakens-windows-mobile/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32644",
          "name" : "32644",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23658",
          "name" : "23658",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21920",
          "name" : "21920",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+Resco+Photo+Viewer+6%2E01+Enabling+Code+Injection+and+Arbitrary+Code+Execution",
          "name" : "http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+Resco+Photo+Viewer+6%2E01+Enabling+Code+Injection+and+Arbitrary+Code+Execution",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0072",
          "name" : "ADV-2007-0072",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Resco Photo Viewer for PocketPC 4.11 and 6.01, as used in mobile devices running Windows Mobile 5.0, 2003, and 2003SE, allows remote attackers to execute arbitrary code via a crafted PNG image."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:resco:photo_viewer:4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:resco:photo_viewer:6.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0112",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "createauction",
            "product" : {
              "product_data" : [ {
                "product_name" : "createauction",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33406",
          "name" : "33406",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2111",
          "name" : "2111",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456272/100/0/threaded",
          "name" : "20070107 createauction (cats.asp) Remote SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21929",
          "name" : "21929",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31356",
          "name" : "createauction-cats-sql-injection(31356)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in cats.asp in createauction allows remote attackers to execute arbitrary SQL commands via the catid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:createauction:createauction:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0113",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "packeteer",
            "product" : {
              "product_data" : [ {
                "product_name" : "packetwise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31656",
          "name" : "31656",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23685",
          "name" : "23685",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2110",
          "name" : "2110",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456267/100/0/threaded",
          "name" : "20070108 Packeteer PacketWise CLI overflow DoS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21933",
          "name" : "21933",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0098",
          "name" : "ADV-2007-0098",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31357",
          "name" : "packetshaper-argument-dos(31357)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Packeteer PacketShaper PacketWise 8.x allows remote authenticated users to cause a denial of service (reset or reboot) via (1) a long traffic class argument to the \"class show\" command or (2) a long POLICY parameter value in clastree.htm."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:packeteer:packetwise:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0114",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "java_system_content_delivery_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32645",
          "name" : "32645",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23630",
          "name" : "23630",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102764-1",
          "name" : "102764",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21908",
          "name" : "21908",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0076",
          "name" : "ADV-2007-0076",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31345",
          "name" : "sun-java-cds-info-disclosure(31345)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Sun Java System Content Delivery Server 5.0 and 5.0 PU1 allows remote attackers to obtain sensitive information regarding \"content details\" via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_content_delivery_server:5.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_content_delivery_server:5.0:pu1:solaris:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0115",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "coppermine",
            "product" : {
              "product_data" : [ {
                "product_name" : "coppermine_photo_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://acid-root.new.fr/poc/19070104.txt",
          "name" : "http://acid-root.new.fr/poc/19070104.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33383",
          "name" : "33383",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2107",
          "name" : "2107",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001218.html",
          "name" : "20070108 Source verify - Coppermine Photo Gallery <= 1.4.10 code injection",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456051/100/0/threaded",
          "name" : "20070105 Coppermine Photo Gallery <= 1.4.10 SQL Injection Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0116",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "digger_solutions",
            "product" : {
              "product_data" : [ {
                "product_name" : "intranet_open_source",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aria-security.com/forum/showthread.php?goto=newpost&t=88",
          "name" : "http://aria-security.com/forum/showthread.php?goto=newpost&t=88",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33379",
          "name" : "33379",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2109",
          "name" : "2109",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456047/100/0/threaded",
          "name" : "20070105 Intranet Open Source Remote Password Disclosure \"intranet.mdb\"",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31308",
          "name" : "intranet-intranet-info-disclosure(31308)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Digger Solutions Intranet Open Source (IOS) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for data/intranet.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:digger_solutions:intranet_open_source:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0117",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31167",
          "name" : "31167",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-05-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-05-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/23653",
          "name" : "23653",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21899",
          "name" : "21899",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0074",
          "name" : "ADV-2007-0074",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permission changes upon execution of a diskutil permission repair operation."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2011-03-08T02:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0118",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "edittag",
            "product" : {
              "product_data" : [ {
                "product_name" : "edittag",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33393",
          "name" : "33393",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33394",
          "name" : "33394",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33395",
          "name" : "33395",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33396",
          "name" : "33396",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/7950",
          "name" : "7950",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456055/100/0/threaded",
          "name" : "20070105 Multiple bugs in EditTag",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21890",
          "name" : "21890",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:edittag:edittag:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0119",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "edittag",
            "product" : {
              "product_data" : [ {
                "product_name" : "edittag",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33390",
          "name" : "33390",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33391",
          "name" : "33391",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33392",
          "name" : "33392",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/7950",
          "name" : "7950",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456055/100/0/threaded",
          "name" : "20070105 Multiple bugs in EditTag",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21891",
          "name" : "21891",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script or HTML via the plain parameter to (1) mkpw_mp.cgi, (2) mkpw.pl, or (3) mkpw.cgi."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:edittag:edittag:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0120",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "acunetix",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_vulnerability_scanner",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0_build_2006-07-17",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/37580",
          "name" : "37580",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21898",
          "name" : "21898",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31279",
          "name" : "acunetix-content-length-dos(31279)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3078",
          "name" : "3078",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of service (application crash) via multiple HTTP requests containing invalid Content-Length values."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:acunetix:web_vulnerability_scanner:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.0_build_2006-07-17"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0121",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "michael_romedahl",
            "product" : {
              "product_data" : [ {
                "product_name" : "ri_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31637",
          "name" : "31637",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23657",
          "name" : "23657",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2108",
          "name" : "2108",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456052/100/0/threaded",
          "name" : "20070105 RI Blog 1.3 XSS Vuln.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21880",
          "name" : "21880",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0083",
          "name" : "ADV-2007-0083",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31317",
          "name" : "riblog-search-xss(31317)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michael_romedahl:ri_blog:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0122",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "coppermine",
            "product" : {
              "product_data" : [ {
                "product_name" : "coppermine_photo_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1_beta_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2_b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2_b-nuke",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://acid-root.new.fr/poc/19070104.txt",
          "name" : "http://acid-root.new.fr/poc/19070104.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35852",
          "name" : "35852",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35853",
          "name" : "35853",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35854",
          "name" : "35854",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35855",
          "name" : "35855",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35856",
          "name" : "35856",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25846",
          "name" : "25846",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2123",
          "name" : "2123",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456051/100/0/threaded",
          "name" : "20070105 Coppermine Photo Gallery <= 1.4.10 SQL Injection Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21894",
          "name" : "21894",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3085",
          "name" : "3085",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.0_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.1_beta_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.2.2_b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.2.2_b-nuke:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0123",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uber_uploader",
            "product" : {
              "product_data" : [ {
                "product_name" : "uber_uploader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2116",
          "name" : "2116",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456045/100/0/threaded",
          "name" : "20070105 Uber Uploader 4.2 Arbitrary File Upload Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31303",
          "name" : "uber-uploader-phtml-file-upload(31303)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in Uber Uploader 4.2 allows remote attackers to upload and execute arbitrary PHP scripts by naming them with a .phtml extension, which bypasses the .php extension check but is still executable on some server configurations."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uber_uploader:uber_uploader:4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0124",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "drupal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/104238",
          "name" : "http://drupal.org/node/104238",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32131",
          "name" : "32131",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23586",
          "name" : "23586",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2115",
          "name" : "2115",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456056/100/0/threaded",
          "name" : "20070105 [DRUPAL-SA-2007-002] Drupal 4.6.11 / 4.7.5 fixes DoS issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21895",
          "name" : "21895",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0051",
          "name" : "ADV-2007-0051",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0125",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kaspersky_lab",
            "product" : {
              "product_data" : [ {
                "product_name" : "kaspersky_antivirus_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=459",
          "name" : "20070105 Kaspersky Antivirus Scan Engine PE File Denial of Service Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32588",
          "name" : "32588",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23575",
          "name" : "23575",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017476",
          "name" : "1017476",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21901",
          "name" : "21901",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0067",
          "name" : "ADV-2007-0067",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31315",
          "name" : "kaspersky-antivirus-pe-dos(31315)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Kaspersky Labs Antivirus Engine 6.0 for Windows and 5.5-10 for Linux before 20070102 enter an infinite loop upon encountering an invalid NumberOfRvaAndSizes value in the Optional Windows Header of a portable executable (PE) file, which allows remote attackers to cause a denial of service (CPU consumption) by scanning a crafted PE file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kaspersky_lab:kaspersky_antivirus_engine:5.5.10:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kaspersky_lab:kaspersky_antivirus_engine:6.0:*:windows:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0126",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "opera",
            "product" : {
              "product_data" : [ {
                "product_name" : "opera_browser",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457",
          "name" : "20070105 Opera Software Opera Web Browser JPG Image DHT Marker Heap Corruption Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html",
          "name" : "SUSE-SA:2007:009",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31574",
          "name" : "31574",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23613",
          "name" : "23613",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23739",
          "name" : "23739",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23771",
          "name" : "23771",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017473",
          "name" : "1017473",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml",
          "name" : "GLSA-200701-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.opera.com/support/search/supsearch.dml?index=852",
          "name" : "http://www.opera.com/support/search/supsearch.dml?index=852",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0060",
          "name" : "ADV-2007-0060",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31305",
          "name" : "opera-jpeg-dht-bo(31305)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bytes in the Define Huffman Table (DHT) marker."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:9.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0127",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "opera",
            "product" : {
              "product_data" : [ {
                "product_name" : "opera_browser",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.02",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458",
          "name" : "20070105 Opera Software Opera Web Browser createSVGTransformFromMatrix Object Typecasting Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html",
          "name" : "SUSE-SA:2007:009",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31575",
          "name" : "31575",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23613",
          "name" : "23613",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23739",
          "name" : "23739",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23771",
          "name" : "23771",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017473",
          "name" : "1017473",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml",
          "name" : "GLSA-200701-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.opera.com/support/search/supsearch.dml?index=851",
          "name" : "http://www.opera.com/support/search/supsearch.dml?index=851",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0060",
          "name" : "ADV-2007-0060",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:1.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:2.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:2.10:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:2.10:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:2.10:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:2.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:3.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:3.00:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:3.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:3.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:3.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:3.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:3.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:3.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:3.62:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:4.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:4.00:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:4.00:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:4.00:beta4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:4.00:beta5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:4.00:beta6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:4.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:4.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:5.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:5.0:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:5.0:beta4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:5.0:beta5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:5.0:beta6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:5.0:beta7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:5.0:beta8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:5.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:5.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:5.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.0:tp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.0:tp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.0:tp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.1:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.06:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.0:beta1_v2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.10:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.11:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.20:beta7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.50:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.54:update1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.54:update2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:7.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:8.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:8.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:8.0:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:8.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:8.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:8.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:8.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:8.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:8.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:8.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:9.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:9.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:9.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "9.02"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T02:28Z",
    "lastModifiedDate" : "2011-03-07T05:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0128",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "digiappz",
            "product" : {
              "product_data" : [ {
                "product_name" : "digirez",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31677",
          "name" : "31677",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23606",
          "name" : "23606",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0053",
          "name" : "ADV-2007-0053",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3081",
          "name" : "3081",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:digiappz:digirez:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0129",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "locazo",
            "product" : {
              "product_data" : [ {
                "product_name" : "locazolist_classifieds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.01a_beta5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35813",
          "name" : "35813",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0052",
          "name" : "ADV-2007-0052",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31242",
          "name" : "locazolist-main-sql-injection(31242)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3073",
          "name" : "3073",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatID parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:locazo:locazolist_classifieds:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.01a_beta5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0130",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "igeneric",
            "product" : {
              "product_data" : [ {
                "product_name" : "ig_calendar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31678",
          "name" : "31678",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23602",
          "name" : "23602",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456044/100/0/threaded",
          "name" : "20070105 IG Calendar SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21873",
          "name" : "21873",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0055",
          "name" : "ADV-2007-0055",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31300",
          "name" : "igcalendar-user-sql-injection(31300)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3082",
          "name" : "3082",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in user.php in iGeneric iG Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:igeneric:ig_calendar:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0131",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jamwiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "jamwiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32581",
          "name" : "32581",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23634",
          "name" : "23634",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=171441&release_id=475663",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=171441&release_id=475663",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21879",
          "name" : "21879",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31296",
          "name" : "jamwiki-permission-security-bypass(31296)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "JAMWiki before 0.5.0 does not properly check permissions during moves of \"read-only or admin-only topics,\" which allows remote attackers to make unauthorized changes to the wiki."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jamwiki:jamwiki:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.4.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T11:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0132",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "igeneric",
            "product" : {
              "product_data" : [ {
                "product_name" : "ig_shop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33385",
          "name" : "33385",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt",
          "name" : "http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/23604",
          "name" : "23604",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456043/100/0/threaded",
          "name" : "20070105 IG Shop remote code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21874",
          "name" : "21874",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0056",
          "name" : "ADV-2007-0056",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31299",
          "name" : "igshop-compareproduct-sql-injection(31299)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3083",
          "name" : "3083",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in compare_product.php in iGeneric iG Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:igeneric:ig_shop:1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0133",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "igeneric",
            "product" : {
              "product_data" : [ {
                "product_name" : "ig_shop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33386",
          "name" : "33386",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0056",
          "name" : "ADV-2007-0056",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in display_review.php in iGeneric iG Shop 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) user_login_cookie parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:igeneric:ig_shop:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T11:28Z",
    "lastModifiedDate" : "2011-03-08T02:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0134",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "igeneric",
            "product" : {
              "product_data" : [ {
                "product_name" : "ig_shop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33387",
          "name" : "33387",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33388",
          "name" : "33388",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt",
          "name" : "http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/23604",
          "name" : "23604",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-June/001664.html",
          "name" : "20070618 Dup: iG Shop 1.4 (page.php) Remote Code Execution Exploit",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456043/100/0/threaded",
          "name" : "20070105 IG Shop remote code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/471722/100/0/threaded",
          "name" : "20070619 iG Shop 1.4 eval Inclusion Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21875",
          "name" : "21875",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0056",
          "name" : "ADV-2007-0056",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31301",
          "name" : "igshop-cartpage-code-execution(31301)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3083",
          "name" : "3083",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php.  NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:igeneric:ig_shop:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:igeneric:ig_shop:1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0135",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aratix",
            "product" : {
              "product_data" : [ {
                "product_name" : "aratix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2.2_beta_11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33405",
          "name" : "33405",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/exploitalert/1698",
          "name" : "http://securityreason.com/exploitalert/1698",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001219.html",
          "name" : "20070108 Source verify of Aratix RFI",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0054",
          "name" : "ADV-2007-0054",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31282",
          "name" : "aratix-init-file-include(31282)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3079",
          "name" : "3079",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the current_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aratix:aratix:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.2.2_beta_11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0136",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "drupal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/files/sa-2007-001/advisory.txt",
          "name" : "http://drupal.org/files/sa-2007-001/advisory.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://drupal.org/node/104233",
          "name" : "http://drupal.org/node/104233",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://marc.info/?l=full-disclosure&m=116799778408115&w=2",
          "name" : "20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://osvdb.org/32139",
          "name" : "32139",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://osvdb.org/32140",
          "name" : "32140",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456054/100/100/threaded",
          "name" : "20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes XSS issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0050",
          "name" : "ADV-2007-0050",
          "refsource" : "VUPEN",
          "tags" : [ "Not Applicable" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31311",
          "name" : "drupal-core-unspecified-xss(31311)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "4.6.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "4.7.0",
          "versionEndExcluding" : "4.7.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T11:28Z",
    "lastModifiedDate" : "2018-10-17T18:39Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0137",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "serendipitynz",
            "product" : {
              "product_data" : [ {
                "product_name" : "serene_bach",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.18r",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.05r",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.08d",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "serene_bach_sb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.13d",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/jp/JVN%2365500885/index.html",
          "name" : "JVN#65500885",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32580",
          "name" : "32580",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23623",
          "name" : "23623",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017470",
          "name" : "1017470",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://serenebach.net/log/sb119R.html",
          "name" : "http://serenebach.net/log/sb119R.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://serenebach.net/log/sb209R.html",
          "name" : "http://serenebach.net/log/sb209R.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21884",
          "name" : "21884",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0065",
          "name" : "ADV-2007-0065",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31302",
          "name" : "serene-bach-unspecified-xss(31302)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in SimpleBoxes/SerendipityNZ Serene Bach 2.05R and earlier, and 2.08D and earlier in the 2.08 series; and (2) sb 1.13D and earlier, and 1.18R and earlier in the 1.18 series; allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:serendipitynz:serene_bach:1.18r:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:serendipitynz:serene_bach:2.05r:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:serendipitynz:serene_bach:2.08d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:serendipitynz:serene_bach_sb:1.13d:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T11:28Z",
    "lastModifiedDate" : "2017-07-29T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0138",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fersch",
            "product" : {
              "product_data" : [ {
                "product_name" : "formbankserver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32546",
          "name" : "32546",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23539",
          "name" : "23539",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31216",
          "name" : "formbankserver-formbank-dos(31216)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with (1) AbfrageForm or (2) EingabeForm, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ sequences in the Name parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fersch:formbankserver:1.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T11:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0139",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "openvms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3_2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIMUP01-V0703-2.txt",
          "name" : "ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIMUP01-V0703-2.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "ftp://ftp.itrc.hp.com/openvms_patches/vax/V7.3/VAX_DNVOSIMUP01-V0703.txt",
          "name" : "ftp://ftp.itrc.hp.com/openvms_patches/vax/V7.3/VAX_DNVOSIMUP01-V0703.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://osvdb.org/32583",
          "name" : "32583",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32584",
          "name" : "32584",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32585",
          "name" : "32585",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32586",
          "name" : "32586",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23636",
          "name" : "23636",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0063",
          "name" : "ADV-2007-0063",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the DECnet-Plus 7.3-2 feature in DECnet/OSI 7.3-2 for OpenVMS ALPHA, and the DECnet-Plus 7.3 feature in DECnet/OSI 7.3 for OpenVMS VAX, allows attackers to obtain \"unintended privileged access to data and system resources\" via unspecified vectors, related to (1) [SYSEXE]CTF$UI.EXE, (2) [SYSMSG]CTF$MESSAGES.EXE, (3) [SYSHLP]CTF$HELP.HLB, and (4) [SYSMGR]CTF$STARTUP.COM."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openvms:7.3:*:openvms_vax:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openvms:7.3_2:*:openvms_vax:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T11:28Z",
    "lastModifiedDate" : "2011-03-08T02:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0140",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kolayindir_download",
            "product" : {
              "product_data" : [ {
                "product_name" : "kolayindir_download",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31625",
          "name" : "31625",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23645",
          "name" : "23645",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2122",
          "name" : "2122",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456068/100/0/threaded",
          "name" : "20070105 Kolayindir Download (Yenionline) (tr) SqL Injection Vuln.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21889",
          "name" : "21889",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0079",
          "name" : "ADV-2007-0079",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31320",
          "name" : "kolayindirdownload-down-sql-injection(31320)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in down.asp in Kolayindir Download (Yenionline) allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kolayindir_download:kolayindir_download:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0141",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "yet_another_link_directory",
            "product" : {
              "product_data" : [ {
                "product_name" : "yet_another_link_directory",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31626",
          "name" : "31626",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23646",
          "name" : "23646",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2121",
          "name" : "2121",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456122/100/0/threaded",
          "name" : "20070106 Yet Another Link Directory v1.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21904",
          "name" : "21904",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0082",
          "name" : "ADV-2007-0082",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31322",
          "name" : "yald-yald-xss(31322)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in yald.php in Yet Another Link Directory 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yet_another_link_directory:yet_another_link_directory:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0142",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "shopstorenow",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-commerce_shopping_cart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31665",
          "name" : "31665",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23642",
          "name" : "23642",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2120",
          "name" : "2120",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456127/100/0/threaded",
          "name" : "20070106 shopstorenow (orange.asp) sql injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21905",
          "name" : "21905",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0080",
          "name" : "ADV-2007-0080",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31313",
          "name" : "shopstorenow-orange-sql-injection(31313)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shopstorenow:e-commerce_shopping_cart:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0143",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nune",
            "product" : {
              "product_data" : [ {
                "product_name" : "news_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0_pre2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31208",
          "name" : "31208",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31209",
          "name" : "31209",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23635",
          "name" : "23635",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456242/100/0/threaded",
          "name" : "20070107 NUNE News Script (custom_admin_path) Remote File Include Vulnerablity",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0078",
          "name" : "ADV-2007-0078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31312",
          "name" : "nune-index-archives-file-include(31312)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3090",
          "name" : "3090",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitrary PHP code via a URL in the custom_admin_path parameter to (1) index.php or (2) archives.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nune:news_script:2.0_pre2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0144",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "digitizing_quote_and_ordering_system",
            "product" : {
              "product_data" : [ {
                "product_name" : "digitizing_quote_and_ordering_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31690",
          "name" : "31690",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23652",
          "name" : "23652",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31321",
          "name" : "qos-search-xss(31321)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3089",
          "name" : "3089",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:digitizing_quote_and_ordering_system:digitizing_quote_and_ordering_system:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0145",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bingo_news",
            "product" : {
              "product_data" : [ {
                "product_name" : "bingo_news",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35898",
          "name" : "35898",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017477",
          "name" : "1017477",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31328",
          "name" : "bingo-bnsmrep1-file-include(31328)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in bn_smrep1.php in BinGoPHP News (BP News) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter, a different vector than CVE-2006-4648 and CVE-2006-4649."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bingo_news:bingo_news:3.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0146",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fix_and_chips_computer_services",
            "product" : {
              "product_data" : [ {
                "product_name" : "fix_and_chips_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23625",
          "name" : "23625",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2119",
          "name" : "2119",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32646",
          "name" : "32646",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32647",
          "name" : "32647",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32648",
          "name" : "32648",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32649",
          "name" : "32649",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32650",
          "name" : "32650",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456121/100/0/threaded",
          "name" : "20070106 Fix & Chips CMS v1.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0081",
          "name" : "ADV-2007-0081",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31319",
          "name" : "fixandchips-multiple-scripts-xss(31319)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Fix and Chips CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) delete-announce.php; the (2) Announcement form field in (b) staff.php; the (3) Client Name, (4) Business Name, (5) Street, (6) Address 2, (7) Town/City, (8) Postcode, (9) Phone Number, (10) Email Address and (11) Website Address form fields in (c) new_customer.php; and unspecified fields in (d) search.php and (e) client-results.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fix_and_chips_computer_services:fix_and_chips_cms:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0147",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cuyahoga",
            "product" : {
              "product_data" : [ {
                "product_name" : "cuyahoga",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://cuyahoga.svn.sourceforge.net/viewvc/cuyahoga?view=rev&revision=551",
          "name" : "http://cuyahoga.svn.sourceforge.net/viewvc/cuyahoga?view=rev&revision=551",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://osvdb.org/32643",
          "name" : "32643",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23662",
          "name" : "23662",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.cuyahoga-project.org/10/section.aspx/61",
          "name" : "http://www.cuyahoga-project.org/10/section.aspx/61",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21927",
          "name" : "21927",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cuyahoga before 1.0.1 installs the FCKEditor component with an incorrect deny statement in a Web.config file, which allows remote attackers to upload files when these privileges were intended only for the Administrator and Editor roles."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cuyahoga:cuyahoga:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2008-11-15T06:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0148",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "omnigroup",
            "product" : {
              "product_data" : [ {
                "product_name" : "omniweb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blog.omnigroup.com/2007/01/07/omniweb-552-now-available-and-more-secure/",
          "name" : "http://blog.omnigroup.com/2007/01/07/omniweb-552-now-available-and-more-secure/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31222",
          "name" : "31222",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-07-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-07-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23624",
          "name" : "23624",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.digitalmunition.com/DMA%5B2007-0107a%5D.txt",
          "name" : "http://www.digitalmunition.com/DMA%5B2007-0107a%5D.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.omnigroup.com/applications/omniweb/releasenotes/",
          "name" : "http://www.omnigroup.com/applications/omniweb/releasenotes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456578/100/0/threaded",
          "name" : "20070111 DMA[2007-0107a] OmniWeb Javascript Alert Format String Vulnerabiity and DMA[2007-0109a] Apple Finder Disk Image Volume Label Overflow / DoS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21911",
          "name" : "21911",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0075",
          "name" : "ADV-2007-0075",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31324",
          "name" : "omniweb-alert-format-string(31324)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3098",
          "name" : "3098",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the Javascript alert function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:omnigroup:omniweb:5.5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0149",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ememberspro",
            "product" : {
              "product_data" : [ {
                "product_name" : "ememberspro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33403",
          "name" : "33403",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2118",
          "name" : "2118",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456228/100/0/threaded",
          "name" : "20070107 EMembersPro 1.0 Remote Password Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31329",
          "name" : "ememberspro-users-info-disclosure(31329)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "EMembersPro 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for users.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ememberspro:ememberspro:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0150",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dayfox_designs",
            "product" : {
              "product_data" : [ {
                "product_name" : "dayfox_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31259",
          "name" : "31259",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23661",
          "name" : "23661",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2117",
          "name" : "2117",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456212/100/0/threaded",
          "name" : "20070107 Dayfox Blog Remote File Include Vuln.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0099",
          "name" : "ADV-2007-0099",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31336",
          "name" : "dayfoxblog-index-file-include(31336)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in index.php in Dayfox Blog allow remote attackers to execute arbitrary PHP code via a URL in the (1) page, (2) subject, and (3) q parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dayfox_designs:dayfox_blog:4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0151",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mitisoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "mitisoft",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33409",
          "name" : "33409",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456230/100/0/threaded",
          "name" : "20070107 MitiSoft Remote Password Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31341",
          "name" : "mitisoft-mitisoft-info-disclosure(31341)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "MitiSoft stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for access_MS/MitiSoft.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mitisoft:mitisoft:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0152",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ohhasp",
            "product" : {
              "product_data" : [ {
                "product_name" : "ohhasp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://64.38.62.221/ariasecucom/forum/showthread.php?t=89",
          "name" : "http://64.38.62.221/ariasecucom/forum/showthread.php?t=89",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33381",
          "name" : "33381",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456117/100/0/threaded",
          "name" : "20070106 ohhASP Remote Password Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31342",
          "name" : "ohhasp-ohhasp-info-disclosure(31342)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OhhASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/OhhASP.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ohhasp:ohhasp:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0153",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adam_jarret",
            "product" : {
              "product_data" : [ {
                "product_name" : "ajlogin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33404",
          "name" : "33404",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2127",
          "name" : "2127",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456226/100/0/threaded",
          "name" : "20070107 AJLogin v3.5 Remote Password Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31331",
          "name" : "ajlogin-ajlogin-info-disclosure(31331)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "AJLogin 3.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for ajlogin.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adam_jarret:ajlogin:3.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0154",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webulas",
            "product" : {
              "product_data" : [ {
                "product_name" : "webulas",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33401",
          "name" : "33401",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2126",
          "name" : "2126",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456239/100/0/threaded",
          "name" : "20070107 Webulas Remote Password Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31338",
          "name" : "webulas-db-info-disclosure(31338)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Webulas stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/db.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webulas:webulas:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0155",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "harikaonline",
            "product" : {
              "product_data" : [ {
                "product_name" : "harikaonline",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33410",
          "name" : "33410",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2125",
          "name" : "2125",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456238/100/0/threaded",
          "name" : "20070107 HarikaOnline v2.0 Remote Password Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31339",
          "name" : "harikaonline-harikaonline-info-disclosure(31339)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "HarikaOnline 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for harikaonline.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:harikaonline:harikaonline:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0156",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "m-core",
            "product" : {
              "product_data" : [ {
                "product_name" : "m-core",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33402",
          "name" : "33402",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2124",
          "name" : "2124",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456235/100/0/threaded",
          "name" : "20070107 M-Core Remote Password Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31340",
          "name" : "mcore-uyelik-info-disclosure(31340)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "M-Core stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to db/uyelik.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:m-core:m-core:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0157",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "neon",
            "product" : {
              "product_data" : [ {
                "product_name" : "neon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.26.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.26.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.26.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html",
          "name" : "[cadaver] 20070123 release 0.22.5",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://mailman.webdav.org/pipermail/neon/2007-January/002362.html",
          "name" : "[neon] 20070107 invalid chars cause sigserv in neon",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/39247",
          "name" : "39247",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23751",
          "name" : "23751",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23763",
          "name" : "23763",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23984",
          "name" : "23984",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:013",
          "name" : "MDKSA-2007:013",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_02_sr.html",
          "name" : "SUSE-SR:2007:002",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22035",
          "name" : "22035",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0172",
          "name" : "ADV-2007-0172",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0362",
          "name" : "ADV-2007-0362",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.webdav.org/cadaver/",
          "name" : "http://www.webdav.org/cadaver/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:neon:neon:0.26.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:neon:neon:0.26.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:neon:neon:0.26.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-09T21:28Z",
    "lastModifiedDate" : "2011-03-08T02:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0158",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "acme",
            "product" : {
              "product_data" : [ {
                "product_name" : "thttpd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-787"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://taviso.decsystem.org/research.t2t",
          "name" : "http://taviso.decsystem.org/research.t2t",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "thttpd 2007 has buffer underflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:acme:thttpd:2007:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2019-12-27T18:15Z",
    "lastModifiedDate" : "2020-01-08T19:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0159",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "geoip",
            "product" : {
              "product_data" : [ {
                "product_name" : "geoip",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://arctic.org/~dean/patches/GeoIP-1.4.0-update-vulnerability.patch",
          "name" : "http://arctic.org/~dean/patches/GeoIP-1.4.0-update-vulnerability.patch",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://osvdb.org/31618",
          "name" : "31618",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23880",
          "name" : "23880",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23906",
          "name" : "23906",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:004",
          "name" : "MDKSA-2007:004",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21959",
          "name" : "21959",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-412-1",
          "name" : "USN-412-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0117",
          "name" : "ADV-2007-0117",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0118",
          "name" : "ADV-2007-0118",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31383",
          "name" : "geoip-geoipupdate-directory-traversal(31383)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the GeoIP_update_database_general function in libGeoIP/GeoIPUpdate.c in GeoIP 1.4.0 allows remote malicious update servers (possibly only update.maxmind.com) to overwrite arbitrary files via a .. (dot dot) in the database filename, which is returned by a request to app/update_getfilename."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geoip:geoip:1.4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-10T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0160",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "centericq",
            "product" : {
              "product_data" : [ {
                "product_name" : "centericq",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.9.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.9.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.21",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33408",
          "name" : "33408",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2129",
          "name" : "2129",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017545",
          "name" : "1017545",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200701-20.xml",
          "name" : "GLSA-200701-20",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456255/100/0/threaded",
          "name" : "20070107 TK53 Advisory #1: CenterICQ remote DoS buffer overflow in LiveJournal handling",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21932",
          "name" : "21932",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0306",
          "name" : "ADV-2007-0306",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31330",
          "name" : "centericq-username-bo(31330)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the LiveJournal support (hooks/ljhook.cc) in CenterICQ 4.9.11 through 4.21.0, when using unofficial LiveJournal servers, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by adding the victim as a friend and using long (1) username and (2) real name strings."
        }, {
          "lang" : "en",
          "value" : "Failed exploitation attempts will likely result in a denial-of-service condition."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:centericq:centericq:4.9.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:centericq:centericq:4.9.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:centericq:centericq:4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:centericq:centericq:4.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:centericq:centericq:4.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:centericq:centericq:4.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:centericq:centericq:4.21:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-10T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0161",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "pml_driver_hpz12",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "color_laserjet_4650",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "officejet_4100",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "officejet_5100",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "officejet_5500",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "officejet_6100",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "officejet_7100",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "officejet_d",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "officejet_g",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "officejet_k",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "psc_1100",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "psc_1200",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "psc_1210_all-in-one",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "psc_1300",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "psc_2100",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "psc_2200",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "psc_2400_photosmart_all-in-one",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "psc_2500_photosmart_all-in-one",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "psc_2510_photosmart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "psc_700",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "psc_900",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32654",
          "name" : "32654",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23663",
          "name" : "23663",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2128",
          "name" : "2128",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://secway.org/advisory/AD20070108.txt",
          "name" : "http://secway.org/advisory/AD20070108.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456259/100/0/threaded",
          "name" : "20070108 HP Multiple Products PML Driver Local Privilege Escalation",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21935",
          "name" : "21935",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0094",
          "name" : "ADV-2007-0094",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31361",
          "name" : "pml-driver-config-privilege-escalation(31361)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:pml_driver_hpz12:*:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:color_laserjet_4650:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:officejet_4100:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:officejet_5100:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:officejet_5500:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:officejet_6100:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:officejet_7100:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:officejet_d:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:officejet_g:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:officejet_k:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_1100:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_1200:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_1210_all-in-one:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_1300:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_2100:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_2200:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_2400_photosmart_all-in-one:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_2500_photosmart_all-in-one:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_2510_photosmart:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_700:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_900:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 2.7,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-10T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0162",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "unsanity",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_enhancer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://landonf.bikemonkey.org/code/macosx/MOAB_Day_8.20070109002959.18582.timor.html",
          "name" : "http://landonf.bikemonkey.org/code/macosx/MOAB_Day_8.20070109002959.18582.timor.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32661",
          "name" : "32661",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-08-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-08-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/23649",
          "name" : "23649",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21951",
          "name" : "21951",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31349",
          "name" : "ape-appenhancer-privilege-escalation(31349)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and the (2) /Library/Frameworks/ApplicationEnhancer.framework directory, which allows local users to gain privileges by modifying or replacing the binary or library files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:unsanity:application_enhancer:2.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-10T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0163",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "securekit",
            "product" : {
              "product_data" : [ {
                "product_name" : "securekit_steganography",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://homepage.mac.com/adonismac/Advisory/steg/steganography.html",
          "name" : "http://homepage.mac.com/adonismac/Advisory/steg/steganography.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/31244",
          "name" : "31244",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23639",
          "name" : "23639",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456283/100/0/threaded",
          "name" : "20070106 Cracking Steganography Application in less than ONE minute",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456519/100/0/threaded",
          "name" : "20070107 A Major design Bug in Steganography 1.7.x, 1.8 (latest) (Updated Version)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31378",
          "name" : "steganography-password-security-bypass(31378)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SecureKit Steganography 1.7.1 and 1.8 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing the last 20 bytes of the JPEG image with alternate password information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:securekit:securekit_steganography:1.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:securekit:securekit_steganography:1.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-10T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0164",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "camouflage",
            "product" : {
              "product_data" : [ {
                "product_name" : "camouflage",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html",
          "name" : "http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32651",
          "name" : "32651",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23578",
          "name" : "23578",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456541/100/0/threaded",
          "name" : "20070107 A Major design Bug in Camouflage 1.2.1 (latest)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21939",
          "name" : "21939",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31375",
          "name" : "camouflage-password-security-bypass(31375)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Camouflage 1.2.1 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing certain bytes of the JPEG image with alternate password information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:camouflage:camouflage:1.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-10T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0165",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sunos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31576",
          "name" : "31576",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23700",
          "name" : "23700",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24056",
          "name" : "24056",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017492",
          "name" : "1017492",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102713-1",
          "name" : "102713",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-036.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-036.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21964",
          "name" : "21964",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0110",
          "name" : "ADV-2007-0110",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31366",
          "name" : "solaris-rpcbind-dos(31366)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2210",
          "name" : "oval:org.mitre.oval:def:2210",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5920",
          "name" : "oval:org.mitre.oval:def:5920",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-10T00:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0166",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32726",
          "name" : "32726",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23730",
          "name" : "23730",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.freebsd.org/advisories/FreeBSD-SA-07:01.jail.asc",
          "name" : "FreeBSD-SA-07:01",
          "refsource" : "FREEBSD",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017505",
          "name" : "1017505",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22011",
          "name" : "22011",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 2.7,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T20:28Z",
    "lastModifiedDate" : "2008-11-15T06:39Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0167",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ppc_search_engine",
            "product" : {
              "product_data" : [ {
                "product_name" : "ppc_search_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.61",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "wgs-ppc",
            "product" : {
              "product_data" : [ {
                "product_name" : "wgs-ppc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2134",
          "name" : "2134",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001221.html",
          "name" : "20070109 \"ppc engine\" is WGS-PPC",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33444",
          "name" : "33444",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33445",
          "name" : "33445",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33446",
          "name" : "33446",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33447",
          "name" : "33447",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33448",
          "name" : "33448",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33449",
          "name" : "33449",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33450",
          "name" : "33450",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33451",
          "name" : "33451",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33452",
          "name" : "33452",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33453",
          "name" : "33453",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33454",
          "name" : "33454",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456386/100/0/threaded",
          "name" : "20070109 ppc engine Multiple file inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21961",
          "name" : "21961",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31355",
          "name" : "demoppc-inc-file-include(31355)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3104",
          "name" : "3104",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/; (5) admin.php and (6) index.php in admini/; (7) paypalipn/ipnprocess.php; (8) index.php and (9) registration.php in members/; and (10) ppcbannerclick.php and (11) ppcclick.php in main/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ppc_search_engine:ppc_search_engine:1.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wgs-ppc:wgs-ppc:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-10T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0168",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ca",
            "product" : {
              "product_data" : [ {
                "product_name" : "brightstor_arcserve_backup",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "brightstor_enterprise_backup",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "business_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://livesploit.com/advisories/LS-20061002.pdf",
          "name" : "http://livesploit.com/advisories/LS-20061002.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31327",
          "name" : "31327",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23648",
          "name" : "23648",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017506",
          "name" : "1017506",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp",
          "name" : "http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/662400",
          "name" : "VU#662400",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.lssec.com/advisories/LS-20061002.pdf",
          "name" : "http://www.lssec.com/advisories/LS-20061002.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456616/100/0/threaded",
          "name" : "20070111 ZDI-07-002: CA BrightStor ARCserve Backup Tape Engine Code Execution Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456637",
          "name" : "20070111 LS-20061002 - Computer Associates BrightStor ARCserve Backup Remote Code Execution Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456711",
          "name" : "20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22010",
          "name" : "22010",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0154",
          "name" : "ADV-2007-0154",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-002.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-002.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31442",
          "name" : "brightstor-tapeengine-code-execution(31442)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup:9.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "11.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_enterprise_backup:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:business_protection_suite:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0169",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ca",
            "product" : {
              "product_data" : [ {
                "product_name" : "brightstor_arcserve_backup",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "brightstor_enterprise_backup",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "business_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=467",
          "name" : "20070111 Computer Associates BrightStor ARCserve Backup RPC Engine PFC Request Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31327",
          "name" : "31327",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23648",
          "name" : "23648",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017506",
          "name" : "1017506",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp",
          "name" : "http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/151032",
          "name" : "VU#151032",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/180336",
          "name" : "VU#180336",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456618/100/0/threaded",
          "name" : "20070111 ZDI-07-004: CA BrightStor ARCserve Backup Tape Engine Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456619/100/0/threaded",
          "name" : "20070111 ZDI-07-003: CA BrightStor ARCserve Backup Message Engine Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456711",
          "name" : "20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22005",
          "name" : "22005",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22006",
          "name" : "22006",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0154",
          "name" : "ADV-2007-0154",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-003.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-003.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-004.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-004.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31433",
          "name" : "brightstor-tapeengine-rpc-bo(31433)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31443",
          "name" : "brightstor-messageengine-rpc-bo(31443)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup:9.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "11.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_enterprise_backup:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:business_protection_suite:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0170",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "allmyphp",
            "product" : {
              "product_data" : [ {
                "product_name" : "allmyvisitors",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35904",
          "name" : "35904",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21917",
          "name" : "21917",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31316",
          "name" : "allmyvisitors-index-file-include(31316)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3097",
          "name" : "3097",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the AMV_serverpath parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:allmyphp:allmyvisitors:0.4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0171",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "voice_of_web",
            "product" : {
              "product_data" : [ {
                "product_name" : "allmylinks",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35909",
          "name" : "35909",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21916",
          "name" : "21916",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31314",
          "name" : "allmylinks-index-file-include(31314)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3096",
          "name" : "3096",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AML_opensite parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:voice_of_web:allmylinks:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:voice_of_web:allmylinks:0.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:voice_of_web:allmylinks:0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:voice_of_web:allmylinks:0.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:voice_of_web:allmylinks:0.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:voice_of_web:allmylinks:0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0172",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "voice_of_web",
            "product" : {
              "product_data" : [ {
                "product_name" : "allmyguests",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35915",
          "name" : "35915",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35916",
          "name" : "35916",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35917",
          "name" : "35917",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35919",
          "name" : "35919",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35921",
          "name" : "35921",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35923",
          "name" : "35923",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21918",
          "name" : "21918",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31310",
          "name" : "allmyguests-multiple-file-include(31310)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3093",
          "name" : "3093",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in unspecified parameters to (3) include/submit.inc.php, (4) admin/index.php, (5) include/cm_submit.inc.php, and (6) index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:voice_of_web:allmyguests:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0173",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "l2j",
            "product" : {
              "product_data" : [ {
                "product_name" : "statistik_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.09",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35914",
          "name" : "35914",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21914",
          "name" : "21914",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0097",
          "name" : "ADV-2007-0097",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31309",
          "name" : "l2j-statistik-index-file-include(31309)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3091",
          "name" : "3091",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:l2j:statistik_script:0.09:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0174",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sina",
            "product" : {
              "product_data" : [ {
                "product_name" : "sina",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "uc2006",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=116832852700467&w=2",
          "name" : "20070109 Sina UC ActiveX Multiple Remote Stack Overflow",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32659",
          "name" : "32659",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23638",
          "name" : "23638",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secway.org/advisory/ad20070109EN.txt",
          "name" : "http://secway.org/advisory/ad20070109EN.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456378/100/0/threaded",
          "name" : "20070109 Sina UC ActiveX Multiple Remote Stack Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21958",
          "name" : "21958",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0093",
          "name" : "ADV-2007-0093",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31348",
          "name" : "sinauc-sendchatroomopt-bo(31348)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31350",
          "name" : "sinauc-senddownloadfile-bo(31350)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based multiple buffer overflows in the BRWOSSRE2UC.dll ActiveX Control in Sina UC2006 and earlier allow remote attackers to execute arbitrary code via a long string in the (1) astrVerion parameter to the SendChatRoomOpt function or (2) the astrDownDir parameter to the SendDownLoadFile function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sina:sina:uc2006:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0175",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "b2evolution",
            "product" : {
              "product_data" : [ {
                "product_name" : "b2evolution",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=410568",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=410568",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32027",
          "name" : "32027",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23656",
          "name" : "23656",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30093",
          "name" : "30093",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1568",
          "name" : "DSA-1568",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21953",
          "name" : "21953",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31368",
          "name" : "b2evolution-login-xss(31368)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:b2evolution:b2evolution:1.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:b2evolution:b2evolution:1.8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:b2evolution:b2evolution:1.8.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-11T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0176",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gforge",
            "product" : {
              "product_data" : [ {
                "product_name" : "gforge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31248",
          "name" : "31248",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23675",
          "name" : "23675",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28598",
          "name" : "28598",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2133",
          "name" : "2133",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017482",
          "name" : "1017482",
          "refsource" : "SECTRACK",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1475",
          "name" : "DSA-1475",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.eazel.es/advisory006-gforge-cross-site-scripting-vulnerability.html",
          "name" : "http://www.eazel.es/advisory006-gforge-cross-site-scripting-vulnerability.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456296/100/0/threaded",
          "name" : "20070108 GForge Cross Site Scripting vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21946",
          "name" : "21946",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31346",
          "name" : "gforge-words-xss(31346)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gforge:gforge:4.5.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0177",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mediawiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "mediawiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.5_r14348",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31525",
          "name" : "31525",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23647",
          "name" : "23647",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24889",
          "name" : "24889",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/forum/forum.php?forum_id=652721",
          "name" : "http://sourceforge.net/forum/forum.php?forum_id=652721",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES",
          "name" : "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES",
          "name" : "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES",
          "name" : "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES",
          "name" : "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_6_sr.html",
          "name" : "SUSE-SR:2007:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21956",
          "name" : "21956",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0096",
          "name" : "ADV-2007-0096",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31359",
          "name" : "mediawiki-ajax-unspecified-xss(31359)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.5_r14348:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.9.0:rc2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0178",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php_web_scripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "easy_banner_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33455",
          "name" : "33455",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2132",
          "name" : "2132",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456404/100/0/threaded",
          "name" : "20070108 Easy Banner Pro Version 2.8 <= Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21967",
          "name" : "21967",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31374",
          "name" : "easybannerpro-info-file-include(31374)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_web_scripts:easy_banner_pro:2.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0179",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpkit",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpkit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31266",
          "name" : "31266",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2131",
          "name" : "2131",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456384/100/0/threaded",
          "name" : "20070109 Re: PHPKit 1.6.1 RC2 (faq/faq.php) Remote SQL Injection Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21962",
          "name" : "21962",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpkit:phpkit:1.6.1:rc2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0180",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ef_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "ef_commander",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.75",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32660",
          "name" : "32660",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23659",
          "name" : "23659",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://vuln.sg/efcommander575-en.html",
          "name" : "http://vuln.sg/efcommander575-en.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21969",
          "name" : "21969",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31365",
          "name" : "efcommander-iso-pathname-bo(31365)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in EF Commander 5.75 allows user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories, which produces a large filename that triggers the overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ef_software:ef_commander:5.75:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-11T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0181",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scriptaty",
            "product" : {
              "product_data" : [ {
                "product_name" : "magic_photo_storage_website",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23687",
          "name" : "23687",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456264/100/0/threaded",
          "name" : "20070108 magic photo storage website Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21965",
          "name" : "21965",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0136",
          "name" : "ADV-2007-0136",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31347",
          "name" : "magicphotostorage-config-file-include(31347)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3100",
          "name" : "3100",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scriptaty:magic_photo_storage_website:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0182",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scriptaty",
            "product" : {
              "product_data" : [ {
                "product_name" : "magic_photo_storage_website",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2136",
          "name" : "2136",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32668",
          "name" : "32668",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33411",
          "name" : "33411",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33412",
          "name" : "33412",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33413",
          "name" : "33413",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33414",
          "name" : "33414",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33415",
          "name" : "33415",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33416",
          "name" : "33416",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33417",
          "name" : "33417",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33418",
          "name" : "33418",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33419",
          "name" : "33419",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33420",
          "name" : "33420",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33421",
          "name" : "33421",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33422",
          "name" : "33422",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33423",
          "name" : "33423",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33425",
          "name" : "33425",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33426",
          "name" : "33426",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33427",
          "name" : "33427",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33428",
          "name" : "33428",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33429",
          "name" : "33429",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33430",
          "name" : "33430",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33431",
          "name" : "33431",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33432",
          "name" : "33432",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33433",
          "name" : "33433",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33434",
          "name" : "33434",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33435",
          "name" : "33435",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33436",
          "name" : "33436",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33437",
          "name" : "33437",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33438",
          "name" : "33438",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33439",
          "name" : "33439",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456389/100/0/threaded",
          "name" : "20070108 magic photo storage website Multiple Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21965",
          "name" : "21965",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3) admin_email.php, (4) add_templates.php, (5) admin_paypal_email.php, (6) approve_member.php, (7) delete_member.php, (8) index.php, (9) list_members.php, (10) membership_pricing.php, or (11) send_email.php in admin/; (12) config.php or (13) db_config.php in include/; or (14) add_category.php, (15) add_news.php, (16) change_catalog_template.php, (17) couple_milestone.php, (18) couple_profile.php, (19) delete_category.php, (20) index.php, (21) login.php, (22) logout.php, (23) register.php, (24) upload_photo.php, (25) user_catelog_password.php, (26) user_email.php, (27) user_extend.php, or (28) user_membership_password.php in user/.  NOTE: the include/common_function.php vector is already covered by another candidate from the same date."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scriptaty:magic_photo_storage_website:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0183",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "iplanet_web_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32662",
          "name" : "32662",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23605",
          "name" : "23605",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21977",
          "name" : "21977",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp1:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp10:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp2:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp3:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp4:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp5:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp6:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp7:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp8:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:iplanet_web_server:4.1:sp9:enterprise:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2008-11-15T06:39Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0184",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "getahead",
            "product" : {
              "product_data" : [ {
                "product_name" : "direct_web_remoting",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://getahead.ltd.uk/dwr/changelog",
          "name" : "http://getahead.ltd.uk/dwr/changelog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html",
          "name" : "SUSE-SR:2009:004",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32657",
          "name" : "32657",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23641",
          "name" : "23641",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21955",
          "name" : "21955",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0095",
          "name" : "ADV-2007-0095",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31377",
          "name" : "dwr-include-exclude-security-bypass(31377)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to obtain unauthorized access to public methods via a crafted request that bypasses the include/exclude checks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0185",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "getahead",
            "product" : {
              "product_data" : [ {
                "product_name" : "direct_web_remoting",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://getahead.ltd.uk/dwr/changelog",
          "name" : "http://getahead.ltd.uk/dwr/changelog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html",
          "name" : "SUSE-SR:2009:004",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32658",
          "name" : "32658",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23641",
          "name" : "23641",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21955",
          "name" : "21955",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0095",
          "name" : "ADV-2007-0095",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31382",
          "name" : "dwr-servlet-engine-dos(31382)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to cause a denial of service (memory exhaustion and servlet outage) via unknown vectors related to a large number of calls in a batch."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:getahead:direct_web_remoting:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0186",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "f5",
            "product" : {
              "product_data" : [ {
                "product_name" : "firepass_4100",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html",
          "name" : "20070106 NNL-Labs & MNIN - F5 FirePass Security Advisory",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23627",
          "name" : "23627",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23643",
          "name" : "23643",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mnin.org/advisories/2007_firepass.pdf",
          "name" : "http://www.mnin.org/advisories/2007_firepass.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32737",
          "name" : "32737",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32738",
          "name" : "32738",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32739",
          "name" : "32739",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32740",
          "name" : "32740",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32741",
          "name" : "32741",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32742",
          "name" : "32742",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32743",
          "name" : "32743",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21957",
          "name" : "21957",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://tech.f5.com/home/solutions/sol6919.html",
          "name" : "https://tech.f5.com/home/solutions/sol6919.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://tech.f5.com/home/solutions/sol6920.html",
          "name" : "https://tech.f5.com/home/solutions/sol6920.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the xcho parameter to my.logon.php3; the (2) topblue, (3) midblue, (4) wtopblue, and certain other Custom color parameters in a per action to vdesk/admincon/index.php; the (5) h321, (6) h311, (7) h312, and certain other Front Door custom text color parameters in a per action to vdesk/admincon/index.php; the (8) ua parameter in a bro action to vdesk/admincon/index.php; the (9) app_param and (10) app_name parameters to webyfiers.php; (11) double eval functions; (12) JavaScript contained in an <FP_DO_NOT_TOUCH> element; and (13) the vhost parameter to my.activation.php.  NOTE: it is possible that this candidate overlaps CVE-2006-3550."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass_4100:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2008-09-05T21:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0187",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "f5",
            "product" : {
              "product_data" : [ {
                "product_name" : "firepass",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0141.html",
          "name" : "20070105 NNL-Labs & MNIN - F5 FirePass Security Advisory",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html",
          "name" : "20070106 NNL-Labs & MNIN - F5 FirePass Security Advisory",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/39167",
          "name" : "39167",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23626",
          "name" : "23626",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23640",
          "name" : "23640",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mnin.org/advisories/2007_firepass.pdf",
          "name" : "http://www.mnin.org/advisories/2007_firepass.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21957",
          "name" : "21957",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://tech.f5.com/home/solutions/sol6916.html",
          "name" : "https://tech.f5.com/home/solutions/sol6916.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://tech.f5.com/home/solutions/sol6924.html",
          "name" : "https://tech.f5.com/home/solutions/sol6924.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (3) Unicode encoding, (4) URL-encoded directory traversal or same-directory characters, or (5) upper case letters in the domain name."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2008-11-15T06:39Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0188",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "f5",
            "product" : {
              "product_data" : [ {
                "product_name" : "firepass",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html",
          "name" : "20070106 NNL-Labs & MNIN - F5 FirePass Security Advisory",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23640",
          "name" : "23640",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mnin.org/advisories/2007_firepass.pdf",
          "name" : "http://www.mnin.org/advisories/2007_firepass.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32734",
          "name" : "32734",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21957",
          "name" : "21957",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://tech.f5.com/home/solutions/sol6922.html",
          "name" : "https://tech.f5.com/home/solutions/sol6922.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP address (\"dotless IP address\"), which allows remote authenticated users to connect to the FirePass administrator console and certain other network resources."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2008-09-05T21:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0189",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "geobb",
            "product" : {
              "product_data" : [ {
                "product_name" : "georgian_bulletin_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33440",
          "name" : "33440",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2141",
          "name" : "2141",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001230.html",
          "name" : "20070110 Dispute of GeoBB RFI",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456251/100/0/threaded",
          "name" : "20070107 GeoBB Georgian Bulletin Board Remote File Include Vuln.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31335",
          "name" : "geobb-index-file-include(31335)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  PHP remote file inclusion vulnerability in index.php in GeoBB Georgian Bulletin Board allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.  NOTE: CVE disputes this issue, since GeoBB 1.0 sets $action to a whitelisted value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geobb:georgian_bulletin_board:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0190",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "edit-x",
            "product" : {
              "product_data" : [ {
                "product_name" : "ecommerce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2139",
          "name" : "2139",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456439/100/0/threaded",
          "name" : "20070109 edit-x ecommerce (include_dir) Remote File include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21974",
          "name" : "21974",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0158",
          "name" : "ADV-2007-0158",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31384",
          "name" : "editx-editaddress-file-include(31384)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:edit-x:ecommerce:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0191",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mkportal",
            "product" : {
              "product_data" : [ {
                "product_name" : "mkportal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33399",
          "name" : "33399",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2138",
          "name" : "2138",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456042/100/100/threaded",
          "name" : "20070105 MkPortal Admin XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31304",
          "name" : "mkportal-admin-xss(31304)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in admin.php in MKPortal allows remote attackers to inject arbitrary web script or HTML via two certain fields in a contents_new operation in the ad_contents section."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mkportal:mkportal:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0192",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mkportal",
            "product" : {
              "product_data" : [ {
                "product_name" : "mkportal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33400",
          "name" : "33400",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2137",
          "name" : "2137",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/455894/100/100/threaded",
          "name" : "20070104 MkPortal \"All Guests are Admin\" Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as demonstrated using a getURL of admin.php within a .swf file contained in an IFRAME element, aka the \"All Guests are Admin\" attack."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mkportal:mkportal:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0193",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fon",
            "product" : {
              "product_data" : [ {
                "product_name" : "la_fonera",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33441",
          "name" : "33441",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456128/100/0/threaded",
          "name" : "20070106 FON Router allows anonymous web access",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456344/100/0/threaded",
          "name" : "20070107 Re: FON Router allows anonymous web access",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "FON La Fonera routers do not properly limit DNS service access by unauthenticated clients, which allows remote attackers to tunnel traffic via DNS requests for hosts that should not be accessible before authentication."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fon:la_fonera:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0194",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mkportal",
            "product" : {
              "product_data" : [ {
                "product_name" : "mkportal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1_rc1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33407",
          "name" : "33407",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456257/100/0/threaded",
          "name" : "20070108 MKPortal Full Path Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31333",
          "name" : "mkportal-admin-path-disclosure(31333)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "admin.php in MKPortal M1.1 RC1 allows remote attackers to obtain sensitive information via a direct request with an MK_PATH=1 query string, which reveals the path in an error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mkportal:mkportal:1.1_rc1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0195",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "f5",
            "product" : {
              "product_data" : [ {
                "product_name" : "firepass",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html",
          "name" : "20070106 NNL-Labs & MNIN - F5 FirePass Security Advisory",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23627",
          "name" : "23627",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mnin.org/advisories/2007_firepass.pdf",
          "name" : "http://www.mnin.org/advisories/2007_firepass.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32736",
          "name" : "32736",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21957",
          "name" : "21957",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://tech.f5.com/home/solutions/sol6923.html",
          "name" : "https://tech.f5.com/home/solutions/sol6923.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "my.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to confirm the validity of an LDAP account."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:5.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:f5:firepass:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T05:04Z",
    "lastModifiedDate" : "2008-09-05T21:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0196",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "motionborg",
            "product" : {
              "product_data" : [ {
                "product_name" : "motionborg_web_real_estate",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32718",
          "name" : "32718",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23531",
          "name" : "23531",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21963",
          "name" : "21963",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0143",
          "name" : "ADV-2007-0143",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31360",
          "name" : "motionborg-admincheckuser-sql-injection(31360)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3105",
          "name" : "3105",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters.  NOTE: some details were obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:motionborg:motionborg_web_real_estate:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0197",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          }, {
            "lang" : "en",
            "value" : "CWE-119"
          }, {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305102",
          "name" : "http://docs.info.apple.com/article.html?artnum=305102",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html",
          "name" : "APPLE-SA-2007-02-15",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-09-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-09-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/24198",
          "name" : "24198",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.digitalmunition.com/DMA%5B2007-0109a%5D.txt",
          "name" : "http://www.digitalmunition.com/DMA%5B2007-0109a%5D.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/240880",
          "name" : "VU#240880",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/32714",
          "name" : "32714",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456578/100/0/threaded",
          "name" : "20070111 DMA[2007-0107a] OmniWeb Javascript Alert Format String Vulnerabiity and DMA[2007-0109a] Apple Finder Disk Image Volume Label Overflow / DoS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21980",
          "name" : "21980",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017662",
          "name" : "1017662",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-047A.html",
          "name" : "TA07-047A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0140",
          "name" : "ADV-2007-0140",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31410",
          "name" : "macos-finder-dos(31410)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-11T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0198",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "ip_contact_center_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "ip_contact_center_hosted",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "unified_contact_center_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "unified_contact_center_hosted",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32682",
          "name" : "32682",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23710",
          "name" : "23710",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017499",
          "name" : "1017499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20070110-jtapi.shtml",
          "name" : "20070110 Cisco Unified Contact Center and IP Contact Center JTapi Gateway Vulnerability",
          "refsource" : "CISCO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21988",
          "name" : "21988",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0138",
          "name" : "ADV-2007-0138",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart) via a certain TCP session on the JTapi server port."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:ip_contact_center_enterprise:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:ip_contact_center_enterprise:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:ip_contact_center_hosted:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:ip_contact_center_hosted:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_contact_center_enterprise:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_contact_center_enterprise:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_contact_center_hosted:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:unified_contact_center_hosted:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T11:28Z",
    "lastModifiedDate" : "2011-03-08T02:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0199",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "ios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32683",
          "name" : "32683",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23697",
          "name" : "23697",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017498",
          "name" : "1017498",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20070110-dlsw.shtml",
          "name" : "20070110 DLSw Vulnerability",
          "refsource" : "CISCO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21990",
          "name" : "21990",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0139",
          "name" : "ADV-2007-0139",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5714",
          "name" : "oval:org.mitre.oval:def:5714",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via \"an invalid value in a DLSw message... during the capabilities exchange.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "12.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T11:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0200",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "geoffrey_golliher",
            "product" : {
              "product_data" : [ {
                "product_name" : "axiom_photo_news_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32716",
          "name" : "32716",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23715",
          "name" : "23715",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001233.html",
          "name" : "20070110 source verify - Axiom RFI",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21972",
          "name" : "21972",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0107",
          "name" : "ADV-2007-0107",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31372",
          "name" : "axiom-template-file-include(31372)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3108",
          "name" : "3108",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to execute arbitrary PHP code via a URL in the baseAxiomPath parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geoffrey_golliher:axiom_photo_news_gallery:0.8.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0201",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tis",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_firewall_toolkit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35967",
          "name" : "35967",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017481",
          "name" : "1017481",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ranum.com/security/computer_security/editorials/codetools/",
          "name" : "http://www.ranum.com/security/computer_security/editorials/codetools/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21960",
          "name" : "21960",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31363",
          "name" : "tisfwtk-ftpgw-bo(31363)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the cmd_usr function in ftp-gw in TIS Internet Firewall Toolkit (FWTK) allows remote attackers to execute arbitrary code via a long destination hostname (dest)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tis:internet_firewall_toolkit:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T11:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0202",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alexphpteam",
            "product" : {
              "product_data" : [ {
                "product_name" : "alex_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://acid-root.new.fr/poc/20070107.txt",
          "name" : "http://acid-root.new.fr/poc/20070107.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/31707",
          "name" : "31707",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23637",
          "name" : "23637",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2135",
          "name" : "2135",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456218/100/0/threaded",
          "name" : "20070107 @lex Guestbook <= 4.0.2 Remote Command Execution Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21926",
          "name" : "21926",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0137",
          "name" : "ADV-2007-0137",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31393",
          "name" : "@lexguestbook-index-sql-injection(31393)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3103",
          "name" : "3103",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alexphpteam:alex_guestbook:3.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alexphpteam:alex_guestbook:3.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alexphpteam:alex_guestbook:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alexphpteam:alex_guestbook:4.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0203",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpmyadmin",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpmyadmin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.9.1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32666",
          "name" : "32666",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23702",
          "name" : "23702",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:199",
          "name" : "MDKSA-2007:199",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0",
          "name" : "http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21987",
          "name" : "21987",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0125",
          "name" : "ADV-2007-0125",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.9.1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T11:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0204",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpmyadmin",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpmyadmin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.9.1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32667",
          "name" : "32667",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23702",
          "name" : "23702",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:199",
          "name" : "MDKSA-2007:199",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0",
          "name" : "http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21987",
          "name" : "21987",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0125",
          "name" : "ADV-2007-0125",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31387",
          "name" : "phpmyadmin-unspecified-xss(31387)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.9.2-rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.9.1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T11:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0205",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alexphpteam",
            "product" : {
              "product_data" : [ {
                "product_name" : "alex_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://acid-root.new.fr/poc/20070107.txt",
          "name" : "http://acid-root.new.fr/poc/20070107.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/31708",
          "name" : "31708",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31709",
          "name" : "31709",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2135",
          "name" : "2135",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456218/100/0/threaded",
          "name" : "20070107 @lex Guestbook <= 4.0.2 Remote Command Execution Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21926",
          "name" : "21926",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31397",
          "name" : "@lexguestbook-livreinclude-file-include(31397)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3103",
          "name" : "3103",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via \"..\" sequences in the (1) aj_skin and (2) skin_edit parameters.  NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alexphpteam:alex_guestbook:3.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alexphpteam:alex_guestbook:3.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alexphpteam:alex_guestbook:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alexphpteam:alex_guestbook:4.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-11T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0206",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "openview_network_node_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.50",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32729",
          "name" : "32729",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2140",
          "name" : "2140",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017503",
          "name" : "1017503",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456615/100/0/threaded",
          "name" : "SSRT061174",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22009",
          "name" : "22009",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0153",
          "name" : "ADV-2007-0153",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to read arbitrary files via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.2:*:hp_ux_10.x:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.2:*:hp_ux_11.x:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.2:*:nt_4.x_windows_2000:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.2:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.4:*:hp_ux_11.x:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.4:*:nt_4.x_windows_2000:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.4:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.41:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:hp_ux_11.x:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:windows_2000_xp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.50:*:hp_ux_11.x:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.50:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.50:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.50:*:windows_2000_xp:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-12T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0207",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0208",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/34385",
          "name" : "34385",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22477",
          "name" : "22477",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017639",
          "name" : "1017639",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
          "name" : "TA07-044A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0583",
          "name" : "ADV-2007-0583",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014",
          "name" : "MS07-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A700",
          "name" : "oval:org.mitre.oval:def:700",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2006:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-13T21:28Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0209",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34386",
          "name" : "34386",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22482",
          "name" : "22482",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017639",
          "name" : "1017639",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
          "name" : "TA07-044A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0583",
          "name" : "ADV-2007-0583",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014",
          "name" : "MS07-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A187",
          "name" : "oval:org.mitre.oval:def:187",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2006:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-13T21:28Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0210",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24132",
          "name" : "24132",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/31889",
          "name" : "31889",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22499",
          "name" : "22499",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017634",
          "name" : "1017634",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
          "name" : "TA07-044A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0576",
          "name" : "ADV-2007-0576",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-007",
          "name" : "MS07-007",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A186",
          "name" : "oval:org.mitre.oval:def:186",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Window Image Acquisition (WIA) Service in Microsoft Windows XP SP2 allows local users to gain privileges via unspecified vectors involving an \"unchecked buffer,\" probably a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T20:28Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0211",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "sp1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24126",
          "name" : "24126",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/240796",
          "name" : "VU#240796",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31890",
          "name" : "31890",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22481",
          "name" : "22481",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017633",
          "name" : "1017633",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
          "name" : "TA07-044A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0575",
          "name" : "ADV-2007-0575",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-006",
          "name" : "MS07-006",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A224",
          "name" : "oval:org.mitre.oval:def:224",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the \"detection and registration of new hardware.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T20:28Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0212",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0213",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "exchange_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/153533/Microsoft-Exchange-2003-base64-MIME-Remote-Code-Execution.html",
          "name" : "http://packetstormsecurity.com/files/153533/Microsoft-Exchange-2003-base64-MIME-Remote-Code-Execution.html",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://secunia.com/advisories/25183",
          "name" : "25183",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/343145",
          "name" : "VU#343145",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/34391",
          "name" : "34391",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23809",
          "name" : "23809",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018015",
          "name" : "1018015",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1711",
          "name" : "ADV-2007-1711",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026",
          "name" : "MS07-026",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33889",
          "name" : "exchange-mime-base64-code-execution(33889)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1890",
          "name" : "oval:org.mitre.oval:def:1890",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2007:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-08T23:19Z",
    "lastModifiedDate" : "2020-04-09T13:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0214",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "itanium",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24136",
          "name" : "24136",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/563756",
          "name" : "VU#563756",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31884",
          "name" : "31884",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22478",
          "name" : "22478",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017635",
          "name" : "1017635",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
          "name" : "TA07-044A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0577",
          "name" : "ADV-2007-0577",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-008",
          "name" : "MS07-008",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A125",
          "name" : "oval:org.mitre.oval:def:125",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:itanium:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-13T20:28Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0215",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/25150",
          "name" : "25150",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34393",
          "name" : "34393",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/467988/100/0/threaded",
          "name" : "20070508 ZDI-07-026: Microsoft Excel BIFF File Format Named Graph Record Parsing Stack Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23760",
          "name" : "23760",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018012",
          "name" : "1018012",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1708",
          "name" : "ADV-2007-1708",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-026.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-026.html",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-023",
          "name" : "MS07-023",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33913",
          "name" : "excel-biff-file-bo(33913)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1971",
          "name" : "oval:org.mitre.oval:def:1971",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-05-08T22:19Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0216",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=659",
          "name" : "20080208 Microsoft Office Works Converter Heap Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
          "name" : "HPSBST02314",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28904",
          "name" : "28904",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27657",
          "name" : "27657",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1019386",
          "name" : "1019386",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
          "name" : "TA08-043C",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0513/references",
          "name" : "ADV-2008-0513",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-011",
          "name" : "MS08-011",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5309",
          "name" : "oval:org.mitre.oval:def:5309",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka \"Microsoft Works File Converter Input Validation Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2008-02-12T23:00Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0217",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=473",
          "name" : "20070213 Microsoft 'wininet.dll' FTP Reply Null Termination Heap Corruption Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24156",
          "name" : "24156",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/613564",
          "name" : "VU#613564",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31892",
          "name" : "31892",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/462303/100/0/threaded",
          "name" : "20070309 MS07-016 FTP Response DOS PoC",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22489",
          "name" : "22489",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017642",
          "name" : "1017642",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
          "name" : "TA07-044A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0584",
          "name" : "ADV-2007-0584",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-016",
          "name" : "MS07-016",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1141",
          "name" : "oval:org.mitre.oval:def:1141",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:sp4:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:gold:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:gold:*:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:gold:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0218",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=542",
          "name" : "20070612 Microsoft License Manager and urlmon.dll COM Object Interaction Invalid Memory Access Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35348",
          "name" : "35348",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25627",
          "name" : "25627",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1018235",
          "name" : "1018235",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/471947/100/0/threaded",
          "name" : "SSRT071438",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24372",
          "name" : "24372",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-163A.html",
          "name" : "TA07-163A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2153",
          "name" : "ADV-2007-2153",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-033",
          "name" : "MS07-033",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32106",
          "name" : "webbrowser-object-code-execution(32106)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1084",
          "name" : "oval:org.mitre.oval:def:1084",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:sp4:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:sp1:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:professional_x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:itanium:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:gold:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:gold:x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-06-12T19:30Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0219",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24156",
          "name" : "24156",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/771788",
          "name" : "VU#771788",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31893",
          "name" : "31893",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/31894",
          "name" : "31894",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/31895",
          "name" : "31895",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22504",
          "name" : "22504",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017643",
          "name" : "1017643",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
          "name" : "TA07-044A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0584",
          "name" : "ADV-2007-0584",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-016",
          "name" : "MS07-016",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32427",
          "name" : "ie-com-activex-code-execution(32427)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A257",
          "name" : "oval:org.mitre.oval:def:257",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2006-4697."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:sp4:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:gold:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:gold:*:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:gold:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:gold:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional_x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T23:28Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0220",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "exchange_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/25183",
          "name" : "25183",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/124113",
          "name" : "VU#124113",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/34389",
          "name" : "34389",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23806",
          "name" : "23806",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018015",
          "name" : "1018015",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1711",
          "name" : "ADV-2007-1711",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026",
          "name" : "MS07-026",
          "refsource" : "MS",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33887",
          "name" : "exchange-utf-xss(33887)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1371",
          "name" : "oval:org.mitre.oval:def:1371",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an \"incorrectly handled UTF character set label\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2003:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-08T23:19Z",
    "lastModifiedDate" : "2020-04-09T13:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0221",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "exchange_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-190"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=526",
          "name" : "20070508 Microsoft Exchange Server 2000 IMAP Literal Processing DoS Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25183",
          "name" : "25183",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/34392",
          "name" : "34392",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23810",
          "name" : "23810",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018015",
          "name" : "1018015",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1711",
          "name" : "ADV-2007-1711",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026",
          "name" : "MS07-026",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33890",
          "name" : "exchange-imap-command-dos(33890)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2054",
          "name" : "oval:org.mitre.oval:def:2054",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the \"IMAP Literal Processing Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-08T23:19Z",
    "lastModifiedDate" : "2020-04-09T13:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0222",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457105/100/0/threaded",
          "name" : "20070115 SYMSA-2007-001: Oracle Application Server 10g - Directory Traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458657/100/0/threaded",
          "name" : "20070131 Oracle 10g R2 Enterprise Manager Directory Traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22027",
          "name" : "22027",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the EmChartBean server side component for Oracle Application Server 10g allows remote attackers to read arbitrary files via unknown vectors, probably \"\\..\" sequences in the beanId parameter.  NOTE: this is likely a duplicate of another CVE that Oracle addressed in CPU Jan 2007, but due to lack of details by Oracle, it is unclear which BugID this issue is associated with, so the other CVE cannot be determined.  Possibilities include EM02 (CVE-2007-0292) or EM05 (CVE-2007-0293)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0223",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nicola_asuni",
            "product" : {
              "product_data" : [ {
                "product_name" : "all_in_one_control_panel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.001",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.008",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31641",
          "name" : "31641",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23726",
          "name" : "23726",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=477845",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=477845",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22019",
          "name" : "22019",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31591",
          "name" : "aiocp-cpfunctionsdownloads-sql-injection(31591)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in shared/code/cp_functions_downloads.php in Nicola Asuni All In One Control Panel (AIOCP) before 1.3.009 allows remote attackers to execute arbitrary SQL commands via the download_category parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.001:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.008:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-13T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0224",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "virtual_programming",
            "product" : {
              "product_data" : [ {
                "product_name" : "vp-asp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.09",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32732",
          "name" : "32732",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23699",
          "name" : "23699",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31447",
          "name" : "vpasp-shopgift-sql-injection(31447)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3115",
          "name" : "3115",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_programming:vp-asp:6.09:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-13T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0225",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "virtual_programming",
            "product" : {
              "product_data" : [ {
                "product_name" : "vp-asp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.09",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32733",
          "name" : "32733",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23699",
          "name" : "23699",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31449",
          "name" : "vpasp-shopcustadmin-xss(31449)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3115",
          "name" : "3115",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_programming:vp-asp:6.09:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-13T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0226",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uniforum",
            "product" : {
              "product_data" : [ {
                "product_name" : "uniforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32927",
          "name" : "32927",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23827",
          "name" : "23827",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458060/100/0/threaded",
          "name" : "20070125 uniForum <= v4 (wbsearch.aspx) Remote SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21966",
          "name" : "21966",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31362",
          "name" : "uniforum-wbsearch-sql-injection(31362)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3106",
          "name" : "3106",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL commands via the \"by User\" field (aka the TXbyuser parameter)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uniforum:uniforum:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-13T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0227",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "slocate",
            "product" : {
              "product_data" : [ {
                "product_name" : "slocate",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33465",
          "name" : "33465",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456489/100/0/threaded",
          "name" : "20070110 slocate leaks filenames of protected directories",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456530/100/0/threaded",
          "name" : "20070110 Re: slocate leaks filenames of protected directories",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456593/100/0/threaded",
          "name" : "20070111 Re: slocate leaks filenames of protected directories",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456739/100/0/threaded",
          "name" : "20070112 Re: slocate leaks filenames of protected directories",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464220/30/7320/threaded",
          "name" : "20070329 FLEA-2007-0005-1: slocate",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21989",
          "name" : "21989",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-425-1",
          "name" : "USN-425-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "slocate 3.1 does not properly manage database entries that specify names of files in protected directories, which allows local users to obtain the names of private files.  NOTE: another researcher reports that the issue is not present in slocate 2.7."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:slocate:slocate:3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-13T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0228",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eiqnetworks",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_security_analyzer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0209.html",
          "name" : "20070110 EIQ Networks Network Security Analyzer DoS Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/32725",
          "name" : "32725",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23693",
          "name" : "23693",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21994",
          "name" : "21994",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0147",
          "name" : "ADV-2007-0147",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31428",
          "name" : "eiq-datacollector-dos(31428)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &CONNECTSERVER& (2) &ADDENTRY& (3) &FIN& (4) &START& (5) &LOGPATH& (6) &FWADELTA& (7) &FWALOG& (8) &SETSYNCHRONOUS& (9) &SETPRGFILE&, or (10) &SETREPLYPORT& string to TCP port 10618, which triggers a NULL pointer dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eiqnetworks:enterprise_security_analyzer:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eiqnetworks:enterprise_security_analyzer:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eiqnetworks:enterprise_security_analyzer:2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-13T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0229",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://applefun.blogspot.com/2007/01/moab-10-01-2007-apple-dmg-ufs.html",
          "name" : "http://applefun.blogspot.com/2007/01/moab-10-01-2007-apple-dmg-ufs.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.freebsd.org/pipermail/freebsd-security/2007-January/004218.html",
          "name" : "[freebsd-security] 20070114 MOAB advisories",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-10-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-10-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/23703",
          "name" : "23703",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32684",
          "name" : "32684",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21993",
          "name" : "21993",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017751",
          "name" : "1017751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0141",
          "name" : "ADV-2007-0141",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31409",
          "name" : "macos-ffsmountfs-bo(31409)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes \"allocation of a negative size buffer\" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679.  NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-13T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0230",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cs-cart",
            "product" : {
              "product_data" : [ {
                "product_name" : "cs-cart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31277",
          "name" : "31277",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001223.html",
          "name" : "20070110 [bogus] [ahmed_labib_hilmy at yahoo.com: CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability] (fwd)",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456527/100/0/threaded",
          "name" : "20070109 CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31408",
          "name" : "cscart-install-file-include(31408)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED ** PHP remote file inclusion vulnerability in install.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the install_dir parameter.  NOTE: CVE and third parties dispute this vulnerability because install_dir is defined before use."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cs-cart:cs-cart:1.3.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-13T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0231",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "six_apart",
            "product" : {
              "product_data" : [ {
                "product_name" : "movable_type",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.33",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://golem.ph.utexas.edu/~distler/blog/archives/001102.html",
          "name" : "http://golem.ph.utexas.edu/~distler/blog/archives/001102.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32717",
          "name" : "32717",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23669",
          "name" : "23669",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0142",
          "name" : "ADV-2007-0142",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zackvision.com/weblog/2007/01/movabletype-security-bug.html",
          "name" : "http://www.zackvision.com/weblog/2007/01/movabletype-security-bug.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Movable Type (MT) 3.33, when nofollow is disabled and unmoderated comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Comments field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:six_apart:movable_type:3.33:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-13T02:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0232",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jshop_e-commerce",
            "product" : {
              "product_data" : [ {
                "product_name" : "jshop_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33459",
          "name" : "33459",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2146",
          "name" : "2146",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456591/100/0/threaded",
          "name" : "20070110 Jshop Server 1.3",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21995",
          "name" : "21995",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31425",
          "name" : "jshop-fieldvalidation-file-include(31425)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3113",
          "name" : "3113",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jshop_e-commerce:jshop_server:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-13T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0233",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.71",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36860",
          "name" : "36860",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21983",
          "name" : "21983",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31385",
          "name" : "wordpress-tbid-sql-injection(31385)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3109",
          "name" : "3109",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.  NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:0.6.2:beta_2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:0.6.2.1:beta_2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:0.71:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-13T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0234",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-0243.  Reason: This candidate is a duplicate of CVE-2007-0243.  Notes: All CVE users should reference CVE-2007-0243 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2007-01-17T00:28Z",
    "lastModifiedDate" : "2008-09-11T00:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0235",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "libgtop",
            "product" : {
              "product_data" : [ {
                "product_name" : "libgtop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.14.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugzilla.gnome.org/show_bug.cgi?id=396477",
          "name" : "http://bugzilla.gnome.org/show_bug.cgi?id=396477",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://ftp.gnome.org/pub/gnome/sources/libgtop/2.14/libgtop-2.14.6.news",
          "name" : "http://ftp.gnome.org/pub/gnome/sources/libgtop/2.14/libgtop-2.14.6.news",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32815",
          "name" : "32815",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23736",
          "name" : "23736",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23777",
          "name" : "23777",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23814",
          "name" : "23814",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23840",
          "name" : "23840",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23872",
          "name" : "23872",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24015",
          "name" : "24015",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26367",
          "name" : "26367",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200701-17.xml",
          "name" : "GLSA-200701-17",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1255",
          "name" : "DSA-1255",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:023",
          "name" : "MDKSA-2007:023",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0765.html",
          "name" : "RHSA-2007:0765",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22054",
          "name" : "22054",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018526",
          "name" : "1018526",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-407-1",
          "name" : "USN-407-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0185",
          "name" : "ADV-2007-0185",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0187",
          "name" : "ADV-2007-0187",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31522",
          "name" : "libgtop2-glibtopbo(31522)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-972",
          "name" : "https://issues.rpath.com/browse/RPL-972",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://launchpad.net/bugs/79206",
          "name" : "https://launchpad.net/bugs/79206",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10720",
          "name" : "oval:org.mitre.oval:def:10720",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a process with a long filename that is mapped in its address space, which triggers the overflow in gnome-system-monitor."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libgtop:libgtop:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.14.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T18:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0236",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-14-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-14-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23708",
          "name" : "23708",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017513",
          "name" : "1017513",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32687",
          "name" : "32687",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22041",
          "name" : "22041",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017751",
          "name" : "1017751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0191",
          "name" : "ADV-2007-0191",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3130",
          "name" : "3130",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and possibly execute arbitrary code via a crafted AppleTalk request that triggers a heap-based buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T18:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0237",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lookup",
            "product" : {
              "product_data" : [ {
                "product_name" : "lookup",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=197306",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=197306",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34263",
          "name" : "34263",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24377",
          "name" : "24377",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24590",
          "name" : "24590",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28023",
          "name" : "28023",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200712-07.xml",
          "name" : "GLSA-200712-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1269",
          "name" : "DSA-1269",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23026",
          "name" : "23026",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017792",
          "name" : "1017792",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33052",
          "name" : "lookup-ndebbinary-symlink(33052)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ndeb-binary feature in Lookup (lookup-el) allows local users to overwrite arbitrary files via a symlink attack on temporary files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lookup:lookup:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-19T19:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0238",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openoffice",
            "product" : {
              "product_data" : [ {
                "product_name" : "openoffice",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html",
          "name" : "SUSE-SA:2007:023",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24465",
          "name" : "24465",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24550",
          "name" : "24550",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24588",
          "name" : "24588",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24613",
          "name" : "24613",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24646",
          "name" : "24646",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24647",
          "name" : "24647",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24676",
          "name" : "24676",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24810",
          "name" : "24810",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24906",
          "name" : "24906",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102794-1",
          "name" : "102794",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1270",
          "name" : "DSA-1270",
          "refsource" : "DEBIAN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml",
          "name" : "GLSA-200704-12",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:073",
          "name" : "MDKSA-2007:073",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-openoffice-suite/",
          "name" : "http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-openoffice-suite/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.openoffice.org/security/CVE-2007-0238",
          "name" : "http://www.openoffice.org/security/CVE-2007-0238",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0033.html",
          "name" : "RHSA-2007:0033",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0069.html",
          "name" : "RHSA-2007:0069",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464724/100/0/threaded",
          "name" : "20070404 High Risk Vulnerability in OpenOffice",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23067",
          "name" : "23067",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017799",
          "name" : "1017799",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-444-1",
          "name" : "USN-444-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1032",
          "name" : "ADV-2007-1032",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1117",
          "name" : "ADV-2007-1117",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33112",
          "name" : "openoffice-starcalc-bo(33112)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.foresightlinux.org/browse/FL-211",
          "name" : "https://issues.foresightlinux.org/browse/FL-211",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1118",
          "name" : "https://issues.rpath.com/browse/RPL-1118",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8968",
          "name" : "oval:org.mitre.oval:def:8968",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in filter\\starcalc\\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openoffice:openoffice:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-21T19:19Z",
    "lastModifiedDate" : "2018-10-16T16:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0239",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openoffice",
            "product" : {
              "product_data" : [ {
                "product_name" : "openoffice",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html",
          "name" : "SUSE-SA:2007:023",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24465",
          "name" : "24465",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24550",
          "name" : "24550",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24588",
          "name" : "24588",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24613",
          "name" : "24613",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24646",
          "name" : "24646",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24647",
          "name" : "24647",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24676",
          "name" : "24676",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24810",
          "name" : "24810",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24906",
          "name" : "24906",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102807-1",
          "name" : "102807",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1270",
          "name" : "DSA-1270",
          "refsource" : "DEBIAN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml",
          "name" : "GLSA-200704-12",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:073",
          "name" : "MDKSA-2007:073",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0033.html",
          "name" : "RHSA-2007:0033",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0069.html",
          "name" : "RHSA-2007:0069",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22812",
          "name" : "22812",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017799",
          "name" : "1017799",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-444-1",
          "name" : "USN-444-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1032",
          "name" : "ADV-2007-1032",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1117",
          "name" : "ADV-2007-1117",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33113",
          "name" : "openoffice-shell-command-execution(33113)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.foresightlinux.org/browse/FL-211",
          "name" : "https://issues.foresightlinux.org/browse/FL-211",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1118",
          "name" : "https://issues.rpath.com/browse/RPL-1118",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11422",
          "name" : "oval:org.mitre.oval:def:11422",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in a crafted document."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openoffice:openoffice:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-21T19:19Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0240",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zope",
            "product" : {
              "product_data" : [ {
                "product_name" : "zope",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.10.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html",
          "name" : "SUSE-SR:2007:011",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24017",
          "name" : "24017",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24713",
          "name" : "24713",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25239",
          "name" : "25239",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1275",
          "name" : "DSA-1275",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23084",
          "name" : "23084",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1041",
          "name" : "ADV-2007-1041",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view",
          "name" : "http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33187",
          "name" : "zope-unspecifiedget-xss(33187)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zope:zope:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.10.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-22T18:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0242",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "qt",
            "product" : {
              "product_data" : [ {
                "product_name" : "qt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.asc",
          "name" : "20070901-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/updates/FEDORA-2007-703.shtml",
          "name" : "FEDORA-2007-703",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2011-1324.html",
          "name" : "RHSA-2011:1324",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24699",
          "name" : "24699",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24705",
          "name" : "24705",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24726",
          "name" : "24726",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24727",
          "name" : "24727",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24759",
          "name" : "24759",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24797",
          "name" : "24797",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24847",
          "name" : "24847",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24889",
          "name" : "24889",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25263",
          "name" : "25263",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26804",
          "name" : "26804",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26857",
          "name" : "26857",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/27108",
          "name" : "27108",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/27275",
          "name" : "27275",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/46117",
          "name" : "46117",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.348591",
          "name" : "SSA:2007-093-03",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-424.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-424.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/39ea4b325a7da742cb8b6995fa585b14.html",
          "name" : "http://support.novell.com/techcenter/psdb/39ea4b325a7da742cb8b6995fa585b14.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/fc79b7f48d739f9c803a24ddad933384.html",
          "name" : "http://support.novell.com/techcenter/psdb/fc79b7f48d739f9c803a24ddad933384.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1292",
          "name" : "DSA-1292",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:074",
          "name" : "MDKSA-2007:074",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:075",
          "name" : "MDKSA-2007:075",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:076",
          "name" : "MDKSA-2007:076",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.nabble.com/Bug-417390:-CVE-2007-0242,--Qt-UTF-8-overlong-sequence-decoding-vulnerability-t3506065.html",
          "name" : "http://www.nabble.com/Bug-417390:-CVE-2007-0242,--Qt-UTF-8-overlong-sequence-decoding-vulnerability-t3506065.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_6_sr.html",
          "name" : "SUSE-SR:2007:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0883.html",
          "name" : "RHSA-2007:0883",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0909.html",
          "name" : "RHSA-2007:0909",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23269",
          "name" : "23269",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trolltech.com/company/newsroom/announcements/press.2007-03-30.9172215350",
          "name" : "http://www.trolltech.com/company/newsroom/announcements/press.2007-03-30.9172215350",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-452-1",
          "name" : "USN-452-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1212",
          "name" : "ADV-2007-1212",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33397",
          "name" : "qt-utf8-xss(33397)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1202",
          "name" : "https://issues.rpath.com/browse/RPL-1202",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11510",
          "name" : "oval:org.mitre.oval:def:11510",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qt:qt:3.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qt:qt:4.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-04-03T16:19Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0243",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.1_01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_01a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_08",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_09",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/242",
          "name" : "BEA07-172.00",
          "refsource" : "BEA",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=307177",
          "name" : "http://docs.info.apple.com/article.html?artnum=307177",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00876579",
          "name" : "HPSBUX02196",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html",
          "name" : "APPLE-SA-2007-12-14",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32834",
          "name" : "32834",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23757",
          "name" : "23757",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24189",
          "name" : "24189",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24202",
          "name" : "24202",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24468",
          "name" : "24468",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24993",
          "name" : "24993",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25283",
          "name" : "25283",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26049",
          "name" : "26049",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26119",
          "name" : "26119",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26645",
          "name" : "26645",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/27203",
          "name" : "27203",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28115",
          "name" : "28115",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200702-08.xml",
          "name" : "GLSA-200702-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2158",
          "name" : "2158",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017520",
          "name" : "1017520",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1",
          "name" : "102760",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html",
          "name" : "http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html",
          "name" : "http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200702-07.xml",
          "name" : "GLSA-200702-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/388289",
          "name" : "VU#388289",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_45_java.html",
          "name" : "SUSE-SA:2007:045",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0166.html",
          "name" : "RHSA-2007:0166",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0167.html",
          "name" : "RHSA-2007:0167",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0956.html",
          "name" : "RHSA-2007:0956",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0261.html",
          "name" : "RHSA-2008:0261",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457159/100/0/threaded",
          "name" : "20070117 ZDI-07-005: Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457638/100/0/threaded",
          "name" : "20070121 Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability Prove Of Concept Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22085",
          "name" : "22085",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-022A.html",
          "name" : "TA07-022A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0211",
          "name" : "ADV-2007-0211",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0936",
          "name" : "ADV-2007-0936",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1814",
          "name" : "ADV-2007-1814",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/4224",
          "name" : "ADV-2007-4224",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-005.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-005.html",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31537",
          "name" : "jre-gif-bo(31537)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11073",
          "name" : "oval:org.mitre.oval:def:11073",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:1.5.0:update3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:1.5.0:update4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:1.5.0:update5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:1.5.0:update7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:1.5.0:update8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:*:update9:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.3.1:update16:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update18:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.5.0:update3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.5.0:update4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.5.0:update5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.5.0:update6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.5.0:update7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.5.0:update8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.5.0:update9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.3.1_01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.3.1_01a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.3.1_16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.3.1_18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_08:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_09:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_12:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-17T22:28Z",
    "lastModifiedDate" : "2018-10-30T16:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0244",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "poptop",
            "product" : {
              "product_data" : [ {
                "product_name" : "pptp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/25220",
          "name" : "25220",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25255",
          "name" : "25255",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26987",
          "name" : "26987",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200705-18.xml",
          "name" : "GLSA-200705-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=501476&group_id=44827",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=501476&group_id=44827",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1288",
          "name" : "DSA-1288",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_10_sr.html",
          "name" : "SUSE-SR:2007:010",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_19_sr.html",
          "name" : "SUSE-SR:2007:019",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23886",
          "name" : "23886",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018064",
          "name" : "1018064",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0017/",
          "name" : "2007-0017",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-459-1",
          "name" : "USN-459-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-459-2",
          "name" : "USN-459-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1743",
          "name" : "ADV-2007-1743",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "pptpgre.c in PoPToP Point to Point Tunneling Server (pptpd) before 1.3.4 allows remote attackers to cause a denial of service (PPTP connection tear-down) via (1) GRE packets with out-of-order sequence numbers or (2) certain GRE packets that are processed using a wrong pointer and improperly dequeued."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:alpha:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:amd64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:arm:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:hppa:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-32:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:ia-64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:m68k:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mips:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:mipsel:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:powerpc:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:s390:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:sparc:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:poptop:pptp_server:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "1.3.3"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-11T04:19Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0245",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openoffice",
            "product" : {
              "product_data" : [ {
                "product_name" : "openoffice",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc",
          "name" : "20070602-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35378",
          "name" : "35378",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25648",
          "name" : "25648",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25650",
          "name" : "25650",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25673",
          "name" : "25673",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25705",
          "name" : "25705",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25862",
          "name" : "25862",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25894",
          "name" : "25894",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25905",
          "name" : "25905",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26010",
          "name" : "26010",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26022",
          "name" : "26022",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26476",
          "name" : "26476",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102917-1",
          "name" : "102917",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sw.openoffice.org/source/browse/sw/sw/source/filter/rtf/swparrtf.cxx?rev=1.67",
          "name" : "http://sw.openoffice.org/source/browse/sw/sw/source/filter/rtf/swparrtf.cxx?rev=1.67",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1307",
          "name" : "DSA-1307",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200707-02.xml",
          "name" : "GLSA-200707-02",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:144",
          "name" : "MDKSA-2007:144",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_37_openoffice.html",
          "name" : "SUSE-SA:2007:037",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0406.html",
          "name" : "RHSA-2007:0406",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/471274/100/0/threaded",
          "name" : "20070613 High risk vulnerability in OpenOffice RTF parser",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24450",
          "name" : "24450",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018239",
          "name" : "1018239",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-482-1",
          "name" : "USN-482-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2166",
          "name" : "ADV-2007-2166",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2229",
          "name" : "ADV-2007-2229",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34843",
          "name" : "openoffice-rtf-bo(34843)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1570",
          "name" : "https://issues.rpath.com/browse/RPL-1570",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10002",
          "name" : "oval:org.mitre.oval:def:10002",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a crafted prtdata tag with a length parameter inconsistency, which causes vtable entries to be overwritten."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openoffice:openoffice:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-06-12T21:30Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0246",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gforge",
            "product" : {
              "product_data" : [ {
                "product_name" : "gforge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.16",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://gforge.org/scm/viewvc.php/branches/Branch_4_5/gforge/plugins/scmcvs/www/cvsweb.php?root=gforge&r1=5849&r2=6038&pathrev=6038",
          "name" : "http://gforge.org/scm/viewvc.php/branches/Branch_4_5/gforge/plugins/scmcvs/www/cvsweb.php?root=gforge&r1=5849&r2=6038&pathrev=6038",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/36526",
          "name" : "36526",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25395",
          "name" : "25395",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25416",
          "name" : "25416",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1297",
          "name" : "DSA-1297",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24141",
          "name" : "24141",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1942",
          "name" : "ADV-2007-1942",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34510",
          "name" : "gforge-cvsweb-command-execution(34510)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gforge:gforge:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.5.16"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-29T21:30Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0247",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "squid",
            "product" : {
              "product_data" : [ {
                "product_name" : "squid",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.stable1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.stable2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.stable3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.stable4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.stable5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.stable6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://fedoranews.org/cms/node/2442",
          "name" : "FEDORA-2007-092",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/39839",
          "name" : "39839",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23767",
          "name" : "23767",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23805",
          "name" : "23805",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23810",
          "name" : "23810",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23837",
          "name" : "23837",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23889",
          "name" : "23889",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23921",
          "name" : "23921",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23946",
          "name" : "23946",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200701-22.xml",
          "name" : "GLSA-200701-22",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:026",
          "name" : "MDKSA-2007:026",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_12_squid.html",
          "name" : "SUSE-SA:2007:012",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22079",
          "name" : "22079",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.squid-cache.org/bugs/show_bug.cgi?id=1857",
          "name" : "http://www.squid-cache.org/bugs/show_bug.cgi?id=1857",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12",
          "name" : "http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0003/",
          "name" : "2007-0003",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-414-1",
          "name" : "USN-414-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0199",
          "name" : "ADV-2007-0199",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31523",
          "name" : "squid-multiple-dos(31523)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squid:squid:2.6.stable1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squid:squid:2.6.stable2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squid:squid:2.6.stable3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squid:squid:2.6.stable4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squid:squid:2.6.stable5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squid:squid:2.6.stable6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0248",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "squid",
            "product" : {
              "product_data" : [ {
                "product_name" : "squid",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.stable6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23767",
          "name" : "23767",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23805",
          "name" : "23805",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23889",
          "name" : "23889",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23921",
          "name" : "23921",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23946",
          "name" : "23946",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200701-22.xml",
          "name" : "GLSA-200701-22",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:026",
          "name" : "MDKSA-2007:026",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_12_squid.html",
          "name" : "SUSE-SA:2007:012",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22203",
          "name" : "22203",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.squid-cache.org/bugs/show_bug.cgi?id=1848",
          "name" : "http://www.squid-cache.org/bugs/show_bug.cgi?id=1848",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12",
          "name" : "http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-414-1",
          "name" : "USN-414-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0199",
          "name" : "ADV-2007-0199",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31525",
          "name" : "squid-externalacl-dos(31525)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squid:squid:2.6.stable6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0249",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nwom",
            "product" : {
              "product_data" : [ {
                "product_name" : "nwom_topsites",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33461",
          "name" : "33461",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2149",
          "name" : "2149",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456636/100/0/threaded",
          "name" : "20070111 Nwom topsites v3.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22012",
          "name" : "22012",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in Nwom topsites 3.0 allows remote attackers to inject arbitrary web script or HTML via the o parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nwom:nwom_topsites:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0250",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nwom",
            "product" : {
              "product_data" : [ {
                "product_name" : "nwom_topsites",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33462",
          "name" : "33462",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2149",
          "name" : "2149",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456636/100/0/threaded",
          "name" : "20070111 Nwom topsites v3.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22012",
          "name" : "22012",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "index.php in Nwom topsites 3.0 allows remote attackers to obtain potentially sensitive information via a ' (quote) character in the o parameter, which forces a SQL error."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nwom:nwom_topsites:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0251",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "snort",
            "product" : {
              "product_data" : [ {
                "product_name" : "snort",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.calyptix.com/advisories/CX-2007-01.txt",
          "name" : "http://labs.calyptix.com/advisories/CX-2007-01.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32095",
          "name" : "32095",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33464",
          "name" : "33464",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2165",
          "name" : "2165",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017507",
          "name" : "1017507",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456598/100/0/threaded",
          "name" : "20070111 Calyptix Security Advisory CX-2007-001 - Snort 2.6.1.2 Integer Underflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22004",
          "name" : "22004",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.snort.org/got_source/source.html",
          "name" : "http://www.snort.org/got_source/source.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0152",
          "name" : "ADV-2007-0152",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive information into log files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snort:snort:2.6.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0252",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "easy-content_filemanager",
            "product" : {
              "product_data" : [ {
                "product_name" : "easy-content_filemanager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33463",
          "name" : "33463",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456622/100/0/threaded",
          "name" : "20070111 easy-content filemanager",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in easy-content filemanager allows remote attackers to upload or modify arbitrary files via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:easy-content_filemanager:easy-content_filemanager:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0253",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "grsecurity",
            "product" : {
              "product_data" : [ {
                "product_name" : "grsecurity_kernel_patch",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.grsecurity.net/viewtopic.php?t=1646",
          "name" : "http://forums.grsecurity.net/viewtopic.php?t=1646",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://grsecurity.net/news.php#digitalfud",
          "name" : "http://grsecurity.net/news.php#digitalfud",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.digitalarmaments.com/news_news.shtml",
          "name" : "http://www.digitalarmaments.com/news_news.shtml",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Unspecified vulnerability in the grsecurity patch has unspecified impact and remote attack vectors, a different vulnerability than the expand_stack vulnerability from the Digital Armaments 20070110 pre-advisory.  NOTE: the grsecurity developer has disputed this issue, stating that \"the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities.\"  The developer also cites a past disclosure that was not proven."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2008-09-05T21:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0254",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xine",
            "product" : {
              "product_data" : [ {
                "product_name" : "xine-ui",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31594",
          "name" : "31594",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23709",
          "name" : "23709",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23891",
          "name" : "23891",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23931",
          "name" : "23931",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200701-18.xml",
          "name" : "GLSA-200701-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:027",
          "name" : "MDKSA-2007:027",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:154",
          "name" : "MDKSA-2007:154",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456590/100/0/threaded",
          "name" : "20070111 Xine-ui format string Vulnerabilties.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22002",
          "name" : "22002",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31505",
          "name" : "xineui-errorscreatewindow-format-string(31505)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the errors_create_window function in errors.c in xine-ui allows attackers to execute arbitrary code via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xine:xine-ui:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0255",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xine",
            "product" : {
              "product_data" : [ {
                "product_name" : "xine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.99.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31666",
          "name" : "31666",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23931",
          "name" : "23931",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:027",
          "name" : "MDKSA-2007:027",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:154",
          "name" : "MDKSA-2007:154",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456523/100/0/threaded",
          "name" : "20070110 VLC Format String Vulnerability also in XINE",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22252",
          "name" : "22252",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp:// URI, possibly a variant of CVE-2007-0017."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xine:xine:0.99.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0256",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "videolan",
            "product" : {
              "product_data" : [ {
                "product_name" : "vlc_media_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.6a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://downloads.securityfocus.com/vulnerabilities/exploits/22003.py",
          "name" : "http://downloads.securityfocus.com/vulnerabilities/exploits/22003.py",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/39022",
          "name" : "39022",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://wiki.videolan.org/Changelog/0.8.6b",
          "name" : "http://wiki.videolan.org/Changelog/0.8.6b",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22003",
          "name" : "22003",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31515",
          "name" : "vlcmediaplayer-wmv-dos(31515)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14698",
          "name" : "oval:org.mitre.oval:def:14698",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:videolan:vlc_media_player:0.8.6a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0257",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "grsecurity",
            "product" : {
              "product_data" : [ {
                "product_name" : "grsecurity_kernel_patch",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.grsecurity.net/viewtopic.php?t=1646",
          "name" : "http://forums.grsecurity.net/viewtopic.php?t=1646",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://grsecurity.net/news.php#digitalfud",
          "name" : "http://grsecurity.net/news.php#digitalfud",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32727",
          "name" : "32727",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23713",
          "name" : "23713",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017509",
          "name" : "1017509",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.digitalarmaments.com/news_news.shtml",
          "name" : "http://www.digitalarmaments.com/news_news.shtml",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.digitalarmaments.com/pre2007-00018659.html",
          "name" : "http://www.digitalarmaments.com/pre2007-00018659.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456626/100/0/threaded",
          "name" : "20070111 Digital Armaments Security Pre-Advisory 11.01.2007: Grsecurity Kernel PaX - Local root vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456722/100/0/threaded",
          "name" : "20070112 Lies? [Was: Re: Digital Armaments Security Pre-Advisory11.01.2007: Grsecurity Kernel PaX - Local root vulnerability]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457509/100/0/threaded",
          "name" : "20070120 Digital Armaments Security Advisory 20.01.2007: Grsecurity Kernel PaX Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/462302/100/100/threaded",
          "name" : "20070309 Re: Digital Armaments Security Advisory 20.01.2007: Grsecurity Kernel PaX Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22014",
          "name" : "22014",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0155",
          "name" : "ADV-2007-0155",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed this issue, stating that \"the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities.\"  The developer also cites a past disclosure that was not proven.  As of 20070120, the original researcher has released demonstration code."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:1.9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0258",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fastilo",
            "product" : {
              "product_data" : [ {
                "product_name" : "fastilo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensolution",
            "product" : {
              "product_data" : [ {
                "product_name" : "quick.car",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://14house.blogspot.com/2007/01/fastilo-open-source-shopping-cart-vuln.html",
          "name" : "http://14house.blogspot.com/2007/01/fastilo-open-source-shopping-cart-vuln.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/32730",
          "name" : "32730",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32731",
          "name" : "32731",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23733",
          "name" : "23733",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23738",
          "name" : "23738",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/21971",
          "name" : "21971",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22007",
          "name" : "22007",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0156",
          "name" : "ADV-2007-0156",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0157",
          "name" : "ADV-2007-0157",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31475",
          "name" : "quickcart-p-xss(31475)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in (1) Fastilo 2.0 and (2) Open Solution Quick.Cart 2.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fastilo:fastilo:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opensolution:quick.car:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0259",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ezboxx",
            "product" : {
              "product_data" : [ {
                "product_name" : "ezboxx_portal_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "beta_0.7.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32829",
          "name" : "32829",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33470",
          "name" : "33470",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.bugsec.com/articles.php?Security=20",
          "name" : "http://www.bugsec.com/articles.php?Security=20",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456699/100/0/threaded",
          "name" : "20070111 Ezboxx multiple vulnerabilities.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0208",
          "name" : "ADV-2007-0208",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via an invalid cat parameter to boxx/knowledgebase.asp, which reveals the path in an error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ezboxx:ezboxx_portal_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "beta_0.7.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0260",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "naig",
            "product" : {
              "product_data" : [ {
                "product_name" : "naig",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33472",
          "name" : "33472",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2145",
          "name" : "2145",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001239.html",
          "name" : "20070112 Fwd: Naig <= 0.5.2 (this_path) Remote File Include Vulnerability",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456744/100/0/threaded",
          "name" : "20070112 Naig <= 0.5.2 (this_path) Remote File Include Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456785/100/0/threaded",
          "name" : "20070113 Re: Naig <= 0.5.2 (this_path) Remote File Include Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  PHP remote file inclusion vulnerability in index.php in Naig 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the this_path parameter.  NOTE: a reliable third party disputes this vulnerability because this_path is defined before use."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:naig:naig:0.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0261",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "snews",
            "product" : {
              "product_data" : [ {
                "product_name" : "snews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.30",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32817",
          "name" : "32817",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23746",
          "name" : "23746",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22025",
          "name" : "22025",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31535",
          "name" : "snews-image-file-upload(31535)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3116",
          "name" : "3116",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snews:snews:1.5.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:snews:snews:1.5.30:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0262",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33458",
          "name" : "33458",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456731/100/0/threaded",
          "name" : "20070112 Wordpress disclosure of Table Prefix Weakness",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.1:alpha_3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0263",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "total_commander",
            "product" : {
              "product_data" : [ {
                "product_name" : "total_commander",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/39837",
          "name" : "39837",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.ghisler.com/whatsnew.htm",
          "name" : "http://www.ghisler.com/whatsnew.htm",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22033",
          "name" : "22033",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Total Commander before 6.5.6 allows user-assisted remote attackers to delete arbitrary files and corrupt a filesystem via a crafted RAR file.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:total_commander:total_commander:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.5.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2008-11-15T06:39Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0264",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "winzip",
            "product" : {
              "product_data" : [ {
                "product_name" : "winzip",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/39800",
          "name" : "39800",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22020",
          "name" : "22020",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argument.  NOTE: this issue may cross privilege boundaries if an application automatically invokes Winzip32.exe for untrusted input filenames, as in the case of a file upload application.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        }, {
          "lang" : "en",
          "value" : "This vulnerability is addressed in the following product release:\r\nWinZip, WinZip, 9.0 SR1"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:winzip:winzip:9.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 2.7,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2008-11-15T06:39Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0265",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ezboxx",
            "product" : {
              "product_data" : [ {
                "product_name" : "portal_system_beta",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32826",
          "name" : "32826",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32827",
          "name" : "32827",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32828",
          "name" : "32828",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33467",
          "name" : "33467",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33468",
          "name" : "33468",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33469",
          "name" : "33469",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23759",
          "name" : "23759",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.bugsec.com/articles.php?Security=20",
          "name" : "http://www.bugsec.com/articles.php?Security=20",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456699/100/0/threaded",
          "name" : "20070111 Ezboxx multiple vulnerabilities.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0208",
          "name" : "ADV-2007-0208",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Ezboxx Portal System Beta 0.7.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pic parameter to custom/piczoom.asp, (2) the nocatname parameter to boxx/user-upload.asp, or (3) the iid parameter to indexes/newscomments.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ezboxx:portal_system_beta:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.7.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0266",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ezboxx",
            "product" : {
              "product_data" : [ {
                "product_name" : "ezboxx_portal_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "beta_0.7.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32825",
          "name" : "32825",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33466",
          "name" : "33466",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23759",
          "name" : "23759",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.bugsec.com/articles.php?Security=20",
          "name" : "http://www.bugsec.com/articles.php?Security=20",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456699/100/0/threaded",
          "name" : "20070111 Ezboxx multiple vulnerabilities.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0208",
          "name" : "ADV-2007-0208",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in boxx/ShowAppendix.asp in Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the iid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ezboxx:ezboxx_portal_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "beta_0.7.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-16T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0267",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.freebsd.org/pipermail/freebsd-security/2007-January/004218.html",
          "name" : "[freebsd-security] 20070114 MOAB advisories",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-12-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-12-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23721",
          "name" : "23721",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/32686",
          "name" : "32686",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22036",
          "name" : "22036",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017751",
          "name" : "1017751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0171",
          "name" : "ADV-2007-0171",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct direct), related to the ufs_dirbad function.  NOTE: a third party states that the FreeBSD issue does not cross privilege boundaries."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T00:28Z",
    "lastModifiedDate" : "2011-06-10T04:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0268",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32907",
          "name" : "32907",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32913",
          "name" : "32913",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32921",
          "name" : "32921",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/221788",
          "name" : "VU#221788",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aq_inv.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aq_inv.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458005/100/0/threaded",
          "name" : "20070124 Oracle Buffer Overflow in DBMS_REPCAT_UNTRUSTED.UNREGISTER_SNAPSHOT",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458475/100/100/threaded",
          "name" : "20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) the Advanced Queuing component and sys.dbms_aqsys.dbms_aq privileges (DB01), (2) Advanced Replication and sys.dbms_repcat_untrusted (DB07), and (3) Oracle Text and ctxload (DB15).  NOTE: Oracle has not publicly claims by reliable researchers that DB01 is for SQL injection in the SYS.DBMS_AQ_INV package, and DB07 is for a buffer overflow in the UNREGISTER_SNAPSHOT procedure in the DBMS_REPCAT_UNTRUSTED package."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0269",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32908",
          "name" : "32908",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe privileges, aka DB02."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0270",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32909",
          "name" : "32909",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.appsecinc.com/resources/alerts/oracle/2007-04.shtml",
          "name" : "http://www.appsecinc.com/resources/alerts/oracle/2007-04.shtml",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458036/100/0/threaded",
          "name" : "20070124 Oracle Buffer Overflow in DBMS_DRS.GET_PROPERTY",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/474050/100/0/threaded",
          "name" : "20070718 Oracle Database Buffer overflow vulnerabilities in procedure DBMS_DRS.GET_PROPERTY (DB03)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via the GET_PROPERTY function in SYS.DBMS_DRS, aka DB03."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0271",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32910",
          "name" : "32910",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.appsecinc.com/resources/alerts/oracle/2007-01.shtml",
          "name" : "http://www.appsecinc.com/resources/alerts/oracle/2007-01.shtml",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458006/100/0/threaded",
          "name" : "20070124 Oracle Buffer Overflow in DBMS_LOGMNR.ADD_LOGFILE",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458475/100/100/threaded",
          "name" : "20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04.  NOTE: Oracle has not disputed a reliable researcher claim that this is a buffer overflow in the ADD_LOGFILE procedure for the SYS.DBMS_LOGMNR package that allows code execution."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0272",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32911",
          "name" : "32911",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.appsecinc.com/resources/alerts/oracle/2007-05.shtml",
          "name" : "http://www.appsecinc.com/resources/alerts/oracle/2007-05.shtml",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458038/100/0/threaded",
          "name" : "20070124 Oracle Multiple Buffer Overflows and DoS attacks in public procedures of MDSYS.MD",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/474047/100/0/threaded",
          "name" : "20070718 Oracle Database Buffer overflows and Denial of service vulnerabilities in public procedures of MDSYS.MD (DB12)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via unspecified vectors involving certain public procedures, aka DB05."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 8.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0273",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32912",
          "name" : "32912",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_xmldb_css2.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_xmldb_css2.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to XMLDB, aka DB06.  NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that DB06 is for multiple cross-site scripting (XSS) vulnerabilities."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0274",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32914",
          "name" : "32914",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32915",
          "name" : "32915",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458037/100/0/threaded",
          "name" : "20070124 Oracle Buffer Overflow in DBMS_LOGREP_UTIL.GET_OBJECT_NAME",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458041/100/0/threaded",
          "name" : "20070124 Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458112/100/100/threaded",
          "name" : "20070125 Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458126/100/0/threaded",
          "name" : "20070125 Re: Oracle Buffer Overflow in DBMS_LOGREP_UTIL.GET_OBJECT_NAME",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458475/100/100/threaded",
          "name" : "20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Database 9.2.0.7 and 10.1.0.5 have unknown impact and attack vectors related to (1) Export and sys.dbms_logrep_util (DB08), and (2) Oracle Streams and sys.dbms_capture_adm_internal privileges (DB09).  NOTE: Oracle has not disputed reliable researcher claims that DB08 is for a buffer overflow in the GET_OBJECT_NAME procedure in the DBMS_LOGREP_UTIL package, and DB09 is for buffer overflows in the CREATE_CAPTURE, ALTER_CAPTURE, and ABORT_TABLE_INSTANTIATION procedures in SYS.DBMS_CAPTURE_ADM_INTERNAL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0275",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32906",
          "name" : "32906",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457193/100/0/threaded",
          "name" : "20070117 [ISecAuditors Security Advisories] Oracle Reports Web Cartridge (RWCGI60) vulnerable to XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to inject arbitrary HTML or web script via the genuser parameter to rwcgi60, aka OWF01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0276",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32916",
          "name" : "32916",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32919",
          "name" : "32919",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32922",
          "name" : "32922",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4 and 9.0.1.5 have unknown impact and attack vectors related to (1) Advanced Security Option and oklist or okdstry (DB10), (2) Oracle Net Services (DB13), and (3) Recovery Manager and oklist (DB16)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0277",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32917",
          "name" : "32917",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0278",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32918",
          "name" : "32918",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32920",
          "name" : "32920",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) NLS Runtime and lmsgen (DB12), and (2) Oracle Text and ctxkbtc (DB14)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0279",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.0.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32881",
          "name" : "32881",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32882",
          "name" : "32882",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32885",
          "name" : "32885",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32886",
          "name" : "32886",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32887",
          "name" : "32887",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:9.2.0.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0280",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32905",
          "name" : "32905",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_buffer_overflow_ons.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_buffer_overflow_ons.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN01.   NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that OPMN01 is for a buffer overflow in Oracle Notification Service (ONS)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:9.0.1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0281",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32883",
          "name" : "32883",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32884",
          "name" : "32884",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1, and 10.1.3.0; and Collaboration Suite 9.0.4.2 and 10.1.2; have unknown impact and attack vectors related to the Oracle HTTP Server, aka (1) OHS03 and (2) OHS04."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:9.0.1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0282",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.2 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN02."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:9.0.1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.2
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.1,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0283",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32896",
          "name" : "32896",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Application Server 9.0.4.3 and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to Oracle Containers for J2EE, aka OC4J02."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0284",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32897",
          "name" : "32897",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32898",
          "name" : "32898",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.3 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2, have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J03 and (2) OC4J04."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0285",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32894",
          "name" : "32894",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 9.0.4.2 and 10.1.2; and E-Business Suite and Applications 11.5.10CU2 has unknown impact and attack vectors related to Oracle Reports Developer, aka REP01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0286",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32901",
          "name" : "32901",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Application Server 10.1.2.0.2 and 10.1.3.0, and Collaboration Suite 10.1.2, has unknown impact and attack vectors related to Containers for J2EE, aka OC4J07."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0287",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32902",
          "name" : "32902",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to Containers for J2EE, aka OC4J08."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.1,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0288",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32903",
          "name" : "32903",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Application Server 10.1.4.0 has unknown impact and attack vectors related to Oracle Internet Directory, aka OID01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.1,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0289",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32895",
          "name" : "32895",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32899",
          "name" : "32899",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32900",
          "name" : "32900",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Collaboration Suite 9.0.4.2 have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J01, (2) OC4J05, and (3) OC4J06."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0290",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32888",
          "name" : "32888",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32890",
          "name" : "32890",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32891",
          "name" : "32891",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32892",
          "name" : "32892",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32893",
          "name" : "32893",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors related to (1) Application Object Library (APPS01), (2) Human Resources (APPS03), (3) Payables (APPS04), (4) Trading Community Architecture (APPS05), and (5) Web Applications Desktop Integrator (APPS06)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0291",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32889",
          "name" : "32889",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle E-Business Suite and Applications 6.2.3 has unknown impact and attack vectors related to Oracle Exchange, aka APPS02."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:6.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0292",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32875",
          "name" : "32875",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32876",
          "name" : "32876",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 have unknown impact and attack vectors related to Oracle Agent, aka (1) EM01 and (2) EM02.  NOTE: EM05 might be related to CVE-2007-0222."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager:10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0293",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32877",
          "name" : "32877",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32878",
          "name" : "32878",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32879",
          "name" : "32879",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors related to (1) Oracle Agent (EM03) and (2) EM04 and (3) EM05 in Enterprise Manager Console.  NOTE: EM05 might be related to CVE-2007-0222."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager:10.2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0294",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32880",
          "name" : "32880",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning & Data Guard Management, aka EM06."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager:10.2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.1,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0295",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterpriseone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.22.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.47.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "peoplesoft_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.22.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.47.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13 and 8.47.11 has unknown impact and attack vectors in PeopleTools, aka PSE01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterpriseone:8.22.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterpriseone:8.47.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise:8.22.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise:8.47.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0296",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterpriseone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.22.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.47.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.48.06",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "peoplesoft_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.22.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.47.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.48.06",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13, 8.47.11, and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE02."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterpriseone:8.22.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterpriseone:8.47.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterpriseone:8.48.06:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise:8.22.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise:8.47.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise:8.48.06:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0297",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterpriseone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.47.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.48.06",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "peoplesoft_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.47.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.48.06",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23794",
          "name" : "23794",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017522",
          "name" : "1017522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22083",
          "name" : "22083",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-017A.html",
          "name" : "TA07-017A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31541",
          "name" : "oracle-cpu-jan2007(31541)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.11 and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE03."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterpriseone:8.47.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterpriseone:8.48.06:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise:8.47.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise:8.48.06:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0298",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dexxaboy",
            "product" : {
              "product_data" : [ {
                "product_name" : "lunarpoll",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2007-January/001236.html",
          "name" : "20070112 Source Verify of LunarPoll PollDir RFI",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/31639",
          "name" : "31639",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23760",
          "name" : "23760",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2152",
          "name" : "2152",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017510",
          "name" : "1017510",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456697/100/0/threaded",
          "name" : "20070112 LunarPoll (PollDir) Remote File Include Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22024",
          "name" : "22024",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0177",
          "name" : "ADV-2007-0177",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31472",
          "name" : "lunarpoll-show-file-include(31472)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3117",
          "name" : "3117",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PollDir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dexxaboy:lunarpoll:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-17T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0299",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-11-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-11-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23725",
          "name" : "23725",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/515792",
          "name" : "VU#515792",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31653",
          "name" : "31653",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017751",
          "name" : "1017751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service (kernel panic) by mounting a crafted Unix File System (UFS) DMG image, which triggers an invalid pointer dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-17T11:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0300",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tlm_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "tlm_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2007-January/001238.html",
          "name" : "20070112 [Bogus - partly] V TLM CMS <= 1.1 (i-accueil.php chemin) Remote File Include Vulnerability (fwd)",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32814",
          "name" : "32814",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23722",
          "name" : "23722",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22021",
          "name" : "22021",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0176",
          "name" : "ADV-2007-0176",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3118",
          "name" : "3118",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that \"register_globals\" is enabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tlm_cms:tlm_cms:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0301",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fdweb",
            "product" : {
              "product_data" : [ {
                "product_name" : "espace_membre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32824",
          "name" : "32824",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23743",
          "name" : "23743",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22040",
          "name" : "22040",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0178",
          "name" : "ADV-2007-0178",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3123",
          "name" : "3123",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that \"register_globals\" is enabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fdweb:espace_membre:2.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fdweb:espace_membre:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0302",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "instantasp",
            "product" : {
              "product_data" : [ {
                "product_name" : "instantasp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32852",
          "name" : "32852",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32853",
          "name" : "32853",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23787",
          "name" : "23787",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2164",
          "name" : "2164",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456970/100/0/threaded",
          "name" : "20070115 InstantForum.NET Multiple Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22052",
          "name" : "22052",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0227",
          "name" : "ADV-2007-0227",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31521",
          "name" : "instantforum-multiple-scripts-xss(31521)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:instantasp:instantasp:4.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0303",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pancake.org",
            "product" : {
              "product_data" : [ {
                "product_name" : "zina",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0_rc1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.pancake.org/zina-changelog-12",
          "name" : "http://www.pancake.org/zina-changelog-12",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22049",
          "name" : "22049",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0181",
          "name" : "ADV-2007-0181",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Zina 1.0rc1 and earlier have unknown impact and attack vectors related to \"Potential security bugs.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pancake.org:zina:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0_rc1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0304",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mint",
            "product" : {
              "product_data" : [ {
                "product_name" : "haber_sistemi",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32820",
          "name" : "32820",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23756",
          "name" : "23756",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0175",
          "name" : "ADV-2007-0175",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3120",
          "name" : "3120",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mint:haber_sistemi:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0305",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "okulsistem_okul_web",
            "product" : {
              "product_data" : [ {
                "product_name" : "otomasyon_sistemi",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32819",
          "name" : "32819",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23755",
          "name" : "23755",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2151",
          "name" : "2151",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456894/100/0/threaded",
          "name" : "20070115 Okul Web Otomasyon Sistemi (etkinlikbak.asp) SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22060",
          "name" : "22060",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0206",
          "name" : "ADV-2007-0206",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3135",
          "name" : "3135",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:okulsistem_okul_web:otomasyon_sistemi:4.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0306",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "digiappz",
            "product" : {
              "product_data" : [ {
                "product_name" : "digiaffiliate",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32818",
          "name" : "32818",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23744",
          "name" : "23744",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22039",
          "name" : "22039",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0179",
          "name" : "ADV-2007-0179",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3122",
          "name" : "3122",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in visu_user.asp in Digiappz DigiAffiliate 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:digiappz:digiaffiliate:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0307",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "poplar_gedcom_viewer",
            "product" : {
              "product_data" : [ {
                "product_name" : "poplar_gedcom_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32807",
          "name" : "32807",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23761",
          "name" : "23761",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22038",
          "name" : "22038",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0174",
          "name" : "ADV-2007-0174",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3121",
          "name" : "3121",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[rootPath] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:poplar_gedcom_viewer:poplar_gedcom_viewer:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:poplar_gedcom_viewer:poplar_gedcom_viewer:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0308",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "plain_black",
            "product" : {
              "product_data" : [ {
                "product_name" : "webgui",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32813",
          "name" : "32813",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23718",
          "name" : "23718",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.plainblack.com/getwebgui/advisories/webgui-7_3_4-beta-released#BUeIjcWiQasypsJxD-YwgQ",
          "name" : "http://www.plainblack.com/getwebgui/advisories/webgui-7_3_4-beta-released#BUeIjcWiQasypsJxD-YwgQ",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22051",
          "name" : "22051",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.3.4 (beta) allows remote attackers to inject arbitrary web script or HTML via Wiki Page titles."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:7.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2008-11-15T06:39Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0309",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "francisco_burzi",
            "product" : {
              "product_data" : [ {
                "product_name" : "php-nuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32863",
          "name" : "32863",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23748",
          "name" : "23748",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2153",
          "name" : "2153",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017511",
          "name" : "1017511",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.neosecurityteam.net/advisories/PHP-Nuke--7.9-Old-Articles-Block-cat-SQL-Injection-vulnerability-31.html",
          "name" : "http://www.neosecurityteam.net/advisories/PHP-Nuke--7.9-Old-Articles-Block-cat-SQL-Injection-vulnerability-31.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456787/100/0/threaded",
          "name" : "20070113 PHP-Nuke <= 7.9 Old-Articles Block \"cat\" SQL Injection vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22037",
          "name" : "22037",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31482",
          "name" : "phpnuke-blockoldarticles-sql-injection(31482)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0310",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bmc",
            "product" : {
              "product_data" : [ {
                "product_name" : "remedy_action_request_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.01.02_patch_1267",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31658",
          "name" : "31658",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23775",
          "name" : "23775",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2162",
          "name" : "2162",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017515",
          "name" : "1017515",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.alighieri.org/advisories/advisory-remedy50102.txt",
          "name" : "http://www.alighieri.org/advisories/advisory-remedy50102.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456949/100/0/threaded",
          "name" : "20070115 Remedy Action Request System 5.01.02 - User Enumeration",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457078/100/0/threaded",
          "name" : "20070116 Re: Remedy Action Request System 5.01.02 - User Enumeration",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22066",
          "name" : "22066",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0204",
          "name" : "ADV-2007-0204",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31527",
          "name" : "rars-login-information-disclosure(31527)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bmc:remedy_action_request_system:5.01.02_patch_1267:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0311",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "texas_imperial_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "wftpd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.25",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "wftpd_pro_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.25",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/22046",
          "name" : "22046",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31517",
          "name" : "wftpd-admn-dos(31517)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3126",
          "name" : "3126",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a long SITE ADMIN command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:texas_imperial_software:wftpd:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.25"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:texas_imperial_software:wftpd_pro_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.25"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0312",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wcsimple_poll",
            "product" : {
              "product_data" : [ {
                "product_name" : "wcsimple_poll",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33539",
          "name" : "33539",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2157",
          "name" : "2157",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456982/100/0/threaded",
          "name" : "20070114 wcSimple Poll (password.txt) Remote Password Disclosure Vulnerablity",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "wcSimple Poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password hashes via a direct request for password.txt."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wcsimple_poll:wcsimple_poll:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0313",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gonicus",
            "product" : {
              "product_data" : [ {
                "product_name" : "gonicus_system_administration",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://oss.gonicus.de/pipermail/gosa/2007-January/002650.html",
          "name" : "[gosa] 20070115 GOsa 2.5.8 released (security fixes!)",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://osvdb.org/32821",
          "name" : "32821",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23749",
          "name" : "23749",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0207",
          "name" : "ADV-2007-0207",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31516",
          "name" : "gosa-unspecified-data-manipulation(31516)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in GONICUS System Administration (GOsa) before 2.5.8 allows remote authenticated users to modify certain settings, including the admin password, via crafted POST requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gonicus:gonicus_system_administration:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.5.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0314",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "article_system",
            "product" : {
              "product_data" : [ {
                "product_name" : "article_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/22017",
          "name" : "22017",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31446",
          "name" : "article-system-includedir-file-include(31446)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3114",
          "name" : "3114",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_DIR parameter to (1) forms.php, (2) issue_edit.php, (3) client.php, and (4) classes.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:article_system:article_system:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0315",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "filezilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "filezilla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.26a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.30",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=475423&group_id=21558",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=475423&group_id=21558",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22057",
          "name" : "22057",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0183",
          "name" : "ADV-2007-0183",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31500",
          "name" : "filezilla-options-queuectrl-bo(31500)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in FileZilla before 2.2.30a allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors related to (1) Options.cpp when storing settings in the registry, and (2) the transfer queue (QueueCtrl.cpp).  NOTE: some of these details are obtained from third party information."
        }, {
          "lang" : "en",
          "value" : "Failed exploit attempts may result in a application level denial-of-service condition."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:0.9.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:0.9.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:0.9.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:2.2.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:2.2.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:2.2.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:2.2.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:2.2.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:2.2.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:2.2.26a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:2.2.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:2.2.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:2.2.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.2.30"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0316",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "all_in_one_control_panel",
            "product" : {
              "product_data" : [ {
                "product_name" : "all_in_one_control_panel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.010",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32809",
          "name" : "32809",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32810",
          "name" : "32810",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23740",
          "name" : "23740",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2166",
          "name" : "2166",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456741",
          "name" : "20070112 AIOCP SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456742",
          "name" : "20070112 AIOCP Login Bypass Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22032",
          "name" : "22032",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0190",
          "name" : "ADV-2007-0190",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31485",
          "name" : "aiocp-cpdownloads-sql-injection(31485)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to shared/code/cp_authorization.php, and the (2) did parameter to public/code/cp_downloads.php, different vectors than CVE-2007-0223."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:all_in_one_control_panel:all_in_one_control_panel:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3.010"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0317",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "filezilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "filezilla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.0_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0_beta4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=477793&group_id=21558",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=477793&group_id=21558",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22063",
          "name" : "22063",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0182",
          "name" : "ADV-2007-0182",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31497",
          "name" : "filezilla-logmessage-format-string(31497)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the LogMessage function in FileZilla before 3.0.0-beta5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted arguments.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:3.0.0_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:3.0.0_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:filezilla:filezilla:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0.0_beta4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0318",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-13-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-13-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23742",
          "name" : "23742",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32685",
          "name" : "32685",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017759",
          "name" : "1017759",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0171",
          "name" : "ADV-2007-0171",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The do_hfs_truncate function in Mac OS X 10.4.8 allows context-dependent attackers to cause a denial of service (kernel panic) via a crafted HFS+ filesystem in a DMG image, which causes an access of an invalid vnode structure during file removal."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0319",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "motive_incorporated",
            "product" : {
              "product_data" : [ {
                "product_name" : "self_service_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "service_activation_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/37710",
          "name" : "37710",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26481",
          "name" : "26481",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1018571",
          "name" : "1018571",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/747233",
          "name" : "VU#747233",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.motive.com/securitybulletin_08122007.asp",
          "name" : "http://www.motive.com/securitybulletin_08122007.asp",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25312",
          "name" : "25312",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2881",
          "name" : "ADV-2007-2881",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045",
          "name" : "MS07-045",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/36034",
          "name" : "activeutils-emaildata-bo(36034)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in the Motive ActiveEmailTest.EmailData (ActiveUtils EmailData) ActiveX control in ActiveUtils.dll in Motive Service Activation Manager 5.1 and Self Service Manager 5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:motive_incorporated:self_service_manager:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:motive_incorporated:service_activation_manager:5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-08-15T19:17Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0320",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "macrovision",
            "product" : {
              "product_data" : [ {
                "product_name" : "installfromtheweb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33530",
          "name" : "33530",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33531",
          "name" : "33531",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24285",
          "name" : "24285",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/181041",
          "name" : "VU#181041",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/MAPG-6UQUDP",
          "name" : "http://www.kb.cert.org/vuls/id/MAPG-6UQUDP",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22672",
          "name" : "22672",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0705",
          "name" : "ADV-2007-0705",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32645",
          "name" : "macrovision-installfromtheweb-activex-bo(32645)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in (a) an ActiveX control (iftw.dll) and (b) Netscape plug-in (npiftw32.dll) for Macrovision (formerly InstallShield) InstallFromTheWeb allow remote attackers to execute arbitrary code via crafted HTML documents."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macrovision:installfromtheweb:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-23T03:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0321",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "macrovision",
            "product" : {
              "product_data" : [ {
                "product_name" : "flexnet_connect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33532",
          "name" : "33532",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24270",
          "name" : "24270",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.installshield.com/kb/view.asp?articleid=Q113020",
          "name" : "http://support.installshield.com/kb/view.asp?articleid=Q113020",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/847993",
          "name" : "VU#847993",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/MAPG-6UERNR",
          "name" : "http://www.kb.cert.org/vuls/id/MAPG-6UERNR",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0706",
          "name" : "ADV-2007-0706",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32678",
          "name" : "macrovision-updateservice-activex-bo(32678)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the Update Service Agent ActiveX Control in isusweb.dll for Macrovision FLEXnet Connect (formerly InstallShield Update Service) allows remote attackers to execute arbitrary code via the Download method."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macrovision:flexnet_connect:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-23T03:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0322",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "intuit",
            "product" : {
              "product_data" : [ {
                "product_name" : "quickbooks",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/26659",
          "name" : "26659",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/907481",
          "name" : "VU#907481",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25544",
          "name" : "25544",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/36462",
          "name" : "quickbooks-activex-bo(36462)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to execute arbitrary code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intuit:quickbooks:*:*:online:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-09-05T19:17Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0323",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rim",
            "product" : {
              "product_data" : [ {
                "product_name" : "teamon_import_object_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35873",
          "name" : "35873",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25218",
          "name" : "25218",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.blackberry.com/btsc/articles/74/KB13142_f.SAL_Public.html",
          "name" : "http://www.blackberry.com/btsc/articles/74/KB13142_f.SAL_Public.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/869641",
          "name" : "VU#869641",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23331",
          "name" : "23331",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1716",
          "name" : "ADV-2007-1716",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027",
          "name" : "MS07-027",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34182",
          "name" : "rim-toimport-activex-bo(34182)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the SetLanguage function in Research In Motion (RIM) TeamOn Import Object ActiveX control (TOImport.dll) allows remote attackers to execute arbitrary code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:teamon_import_object_activex_control:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-08T23:19Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0324",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lizardtech",
            "product" : {
              "product_data" : [ {
                "product_name" : "djvu_browser_plug-in",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33199",
          "name" : "33199",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24149",
          "name" : "24149",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2259",
          "name" : "2259",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/522393",
          "name" : "VU#522393",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.lizardtech.com/products/doc/djvupluginrelease.php",
          "name" : "http://www.lizardtech.com/products/doc/djvupluginrelease.php",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460197/100/0/threaded",
          "name" : "20070215 Lizardtech DjVu Browser Plug-in - Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22569",
          "name" : "22569",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0618",
          "name" : "ADV-2007-0618",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32510",
          "name" : "djvu-browser-multiple-bo(32510)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in the LizardTech DjVu Browser Plug-in before 6.1.1 allow remote attackers to execute arbitrary code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lizardtech:djvu_browser_plug-in:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lizardtech:djvu_browser_plug-in:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lizardtech:djvu_browser_plug-in:6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-15T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0325",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trend_micro",
            "product" : {
              "product_data" : [ {
                "product_name" : "client-server-messaging_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "officescan_corporate_edition",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034288",
          "name" : "http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034288",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33040",
          "name" : "33040",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24193",
          "name" : "24193",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/784369",
          "name" : "VU#784369",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22585",
          "name" : "22585",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017664",
          "name" : "1017664",
          "refsource" : "SECTRACK",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.trendmicro.com/ftp/documentation/readme/osce_70_win_en_securitypatch_1344_readme.txt",
          "name" : "http://www.trendmicro.com/ftp/documentation/readme/osce_70_win_en_securitypatch_1344_readme.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0638",
          "name" : "ADV-2007-0638",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that OfficeScan client was installed using web deployment."
        }, {
          "lang" : "en",
          "value" : "The vendor has issued a fix (7.0 Security Patch - Build 1344; 7.3 Security Patch - Build 1241).\r\n"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:client-server-messaging_security:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan_corporate_edition:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan_corporate_edition:7.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-20T17:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0326",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "photochannel",
            "product" : {
              "product_data" : [ {
                "product_name" : "pni_digital_media_upload_plugin_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/37958",
          "name" : "37958",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26830",
          "name" : "26830",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/854769",
          "name" : "VU#854769",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25685",
          "name" : "25685",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018701",
          "name" : "1018701",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/3181",
          "name" : "ADV-2007-3181",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/36643",
          "name" : "photochannel-photo-upload-bo(36643)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors."
        }, {
          "lang" : "en",
          "value" : "This vulnerability is addressed in the following product release:\r\nPhotoChannel, PNI Digital Media Photo Upload Plugin ActiveX control, 2.0.0.10"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:photochannel:pni_digital_media_upload_plugin_activex_control:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-09-18T20:17Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0328",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "macrovision",
            "product" : {
              "product_data" : [ {
                "product_name" : "flexnet_connect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "update_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36896",
          "name" : "36896",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25501",
          "name" : "25501",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/32842",
          "name" : "32842",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.installshield.com/kb/view.asp?articleid=Q113020",
          "name" : "http://support.installshield.com/kb/view.asp?articleid=Q113020",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html",
          "name" : "http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/524681",
          "name" : "VU#524681",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2017",
          "name" : "ADV-2007-2017",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/3278",
          "name" : "ADV-2008-3278",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34660",
          "name" : "macrovision-dwupdate-command-execution(34660)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macrovision:flexnet_connect:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macrovision:update_service:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macrovision:update_service:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macrovision:update_service:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-06-01T00:30Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0329",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joonas_viljanen",
            "product" : {
              "product_data" : [ {
                "product_name" : "jv2_folder_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32811",
          "name" : "32811",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23724",
          "name" : "23724",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0180",
          "name" : "ADV-2007-0180",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3125",
          "name" : "3125",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathname in the file parameter, as demonstrated by config/gallerysetup.php.  NOTE: this issue might be resultant from a directory traversal vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joonas_viljanen:jv2_folder_gallery:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0330",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ipswitch",
            "product" : {
              "product_data" : [ {
                "product_name" : "ws_ftp_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33476",
          "name" : "33476",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2160",
          "name" : "2160",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456755/100/0/threaded",
          "name" : "20070112 Ipswitch WS_FTP 2007 Professional \"wsftpurl\" access violation vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456901/100/0/threaded",
          "name" : "20070114 Re: Ipswitch WS_FTP 2007 Professional \"wsftpurl\" access violation vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457097/100/0/threaded",
          "name" : "20070116 Re: Ipswitch WS_FTP 2007 Professional \"wsftpurl\" access violation vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22062",
          "name" : "22062",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in wsbho2k0.dll, as used by wsftpurl.exe, in Ipswitch WS_FTP 2007 Professional allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long ftp:// URL in an HTML document, and possibly other vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipswitch:ws_ftp_pro:2007:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0331",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xentraz",
            "product" : {
              "product_data" : [ {
                "product_name" : "liens_dynamiques",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33540",
          "name" : "33540",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456986/100/0/threaded",
          "name" : "20070114 liens_dynamiques xss and admin authentification",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22070",
          "name" : "22070",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31528",
          "name" : "liensdynamiques-liens-xss(31528)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in liens.php3 in liens_dynamiques 2.1 allows remote attackers to inject arbitrary web script or HTML by using the ajouter=1 query string and the add menu."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xentraz:liens_dynamiques:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0332",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xentraz",
            "product" : {
              "product_data" : [ {
                "product_name" : "liens_dynamiques",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33541",
          "name" : "33541",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33542",
          "name" : "33542",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456986/100/0/threaded",
          "name" : "20070114 liens_dynamiques xss and admin authentification",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22068",
          "name" : "22068",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "(1) admin/adminlien.php3 and (2) admin/modif.php3 in liens_dynamiques 2.1 do not require authentication, which allows remote attackers to perform unauthorized administrative actions using a direct request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xentraz:liens_dynamiques:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0333",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "agnitum",
            "product" : {
              "product_data" : [ {
                "product_name" : "outpost_firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33480",
          "name" : "33480",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2163",
          "name" : "2163",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.matousec.com/info/advisories/Outpost-Bypassing-Self-Protection-using-file-links.php",
          "name" : "http://www.matousec.com/info/advisories/Outpost-Bypassing-Self-Protection-using-file-links.php",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456973/100/0/threaded",
          "name" : "20070115 Outpost Bypassing Self-Protection using file links Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22069",
          "name" : "22069",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31529",
          "name" : "outpostfirewall-zwset-privilege-escalation(31529)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Agnitum Outpost Firewall PRO 4.0 allows local users to bypass access restrictions and insert Trojan horse drivers into the product's installation directory by creating links using FileLinkInformation requests with the ZwSetInformationFile function, as demonstrated by modifying SandBox.sys."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:agnitum:outpost_firewall:4.0:*:pro:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0334",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ingate",
            "product" : {
              "product_data" : [ {
                "product_name" : "firewall_and_siparator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32831",
          "name" : "32831",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23737",
          "name" : "23737",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.ingate.com/relnote-451.php",
          "name" : "http://www.ingate.com/relnote-451.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22080",
          "name" : "22080",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0209",
          "name" : "ADV-2007-0209",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31546",
          "name" : "ingate-sip-security-bypass(31546)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the SIP module in InGate Firewall and SIParator before 4.5.1 allows remote attackers to conduct replay attacks on the authentication mechanism via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:ingate:firewall_and_siparator:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.5.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0335",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jax_scripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "jax_petition_book",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3.06",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32835",
          "name" : "32835",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32836",
          "name" : "32836",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23784",
          "name" : "23784",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2161",
          "name" : "2161",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456981/100/0/threaded",
          "name" : "20070114 Jax Petition Book (languagepack) Remote File Include Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456989/100/0/threaded",
          "name" : "20070115 Re: Jax Petition Book (languagepack) Remote File Include Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457077/100/0/threaded",
          "name" : "20070116 Re: Jax Petition Book (languagepack) Remote File Include Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22072",
          "name" : "22072",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0220",
          "name" : "ADV-2007-0220",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31543",
          "name" : "petitionbook-language-file-include(31543)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jax_scripts:jax_petition_book:1.0.3.06:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0336",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rixstep",
            "product" : {
              "product_data" : [ {
                "product_name" : "undercover",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051793.html",
          "name" : "20070115 Rixstep aren't as leet as they thought they were",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22071",
          "name" : "22071",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Undercover.app/Contents/Resources/uc in Rixstep Undercover allows local users to overwrite arbitrary files, probably related to a race condition."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rixstep:undercover:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2008-09-05T21:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0337",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kgb",
            "product" : {
              "product_data" : [ {
                "product_name" : "kgb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31585",
          "name" : "31585",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23768",
          "name" : "23768",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22065",
          "name" : "22065",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0228",
          "name" : "ADV-2007-0228",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31508",
          "name" : "kgb-sesskglogadmin-file-include(31508)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3134",
          "name" : "3134",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skinnn parameter, as demonstrated by invoking kg.php with a postek parameter containing PHP code, which is injected into a file in the kg directory, and then included by sesskglogadmin.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kgb:kgb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0338",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bolintech",
            "product" : {
              "product_data" : [ {
                "product_name" : "dreamftp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32816",
          "name" : "32816",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23731",
          "name" : "23731",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3128",
          "name" : "3128",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with a large number of format string specifiers, which triggers the overflow during processing of the Server Log."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bolintech:dreamftp_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0339",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scriptme",
            "product" : {
              "product_data" : [ {
                "product_name" : "sme_filemailer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.21",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32832",
          "name" : "32832",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23766",
          "name" : "23766",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2154",
          "name" : "2154",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001244.html",
          "name" : "20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457071/100/0/threaded",
          "name" : "20070116 [x0n3-h4ck] SmE FileMailer 1.21 Remote Sql Injextion Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php (aka the login form) in Scriptme SMe FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the Password field (ps parameter).  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scriptme:sme_filemailer:1.21:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0340",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "thwboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "thwboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0_beta_2.84",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32837",
          "name" : "32837",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23735",
          "name" : "23735",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3124",
          "name" : "3124",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execute arbitrary SQL commands via the board[styleid] parameter to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:thwboard:thwboard:*:*:php5:*:*:*:*:*",
          "versionEndIncluding" : "3.0_beta_2.84"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0341",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpmyadmin",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpmyadmin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/456698/100/0/threaded",
          "name" : "20070112 xss in phpmyadmin <= 2.8.1",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456726/100/0/threaded",
          "name" : "20070112 Re: xss in phpmyadmin <= 2.8.1",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.virtuax.be/advisories/Advisory1-12012007.txt",
          "name" : "http://www.virtuax.be/advisories/Advisory1-12012007.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpmyadmin:phpmyadmin:2.8.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0342",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.4_419.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "webkit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "build_18794",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "omnigroup",
            "product" : {
              "product_data" : [ {
                "product_name" : "omniweb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://security-protocols.com/sp-x41-advisory.php",
          "name" : "http://security-protocols.com/sp-x41-advisory.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22059",
          "name" : "22059",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4_419.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:webkit:build_18794:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:omnigroup:omniweb:5.5.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2008-09-05T04:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0343",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openbsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "openbsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23830",
          "name" : "23830",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017518",
          "name" : "1017518",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.openbsd.org/errata.html#icmp6",
          "name" : "[4.0] 008: RELIABILITY FIX: January 16, 2007",
          "refsource" : "OPENBSD",
          "tags" : [ ]
        }, {
          "url" : "http://www.openbsd.org/errata39.html#icmp6",
          "name" : "[3.9] 018: RELIABILITY FIX: January 16, 2007",
          "refsource" : "OPENBSD",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32935",
          "name" : "32935",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22087",
          "name" : "22087",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OpenBSD before 20070116 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via certain IPv6 ICMP (aka ICMP6) echo request packets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2008-09-05T21:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0344",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "colloquy",
            "product" : {
              "product_data" : [ {
                "product_name" : "colloquy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://projects.info-pull.com/moab/MOAB-16-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-16-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/23801",
          "name" : "23801",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/32688",
          "name" : "32688",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22086",
          "name" : "22086",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0238",
          "name" : "ADV-2007-0238",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3139",
          "name" : "3139",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the channel name of an INVITE request, related to the implementation of AlertSheet and AlertPanel in Apple AppKit."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:colloquy:colloquy:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0345",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://projects.info-pull.com/moab/MOAB-15-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-15-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/32700",
          "name" : "32700",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32701",
          "name" : "32701",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32702",
          "name" : "32702",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31530",
          "name" : "macosx-applications-privilege-escalation(31530)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3136",
          "name" : "3136",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and then performing permissions repair via diskutil."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0346",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sme",
            "product" : {
              "product_data" : [ {
                "product_name" : "filemailer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.21",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32832",
          "name" : "32832",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001244.html",
          "name" : "20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0221",
          "name" : "ADV-2007-0221",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31533",
          "name" : "smefilemailer-login-sql-injection(31533)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in SmE FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the us parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sme:filemailer:1.21:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-18T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0347",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cvstrac",
            "product" : {
              "product_data" : [ {
                "product_name" : "cvstrac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052058.html",
          "name" : "20070129 CVSTrac 2.0.0 Denial of Service (DoS) vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/31935",
          "name" : "31935",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23940",
          "name" : "23940",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2192",
          "name" : "2192",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.cvstrac.org/cvstrac/chngview?cn=850",
          "name" : "http://www.cvstrac.org/cvstrac/chngview?cn=850",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.cvstrac.org/cvstrac/tktview?tn=683",
          "name" : "http://www.cvstrac.org/cvstrac/tktview?tn=683",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.008.html",
          "name" : "OpenPKG-SA-2007.008",
          "refsource" : "OPENPKG",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458455/100/0/threaded",
          "name" : "20070129 CVSTrac 2.0.0 Denial of Service (DoS) vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22296",
          "name" : "22296",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0398",
          "name" : "ADV-2007-0398",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the \"'\" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries."
        }, {
          "lang" : "en",
          "value" : "An SQL injection via this technique is somewhat limited as is_eow() bails on whitespace. So while one _can_ do an SQL injection, one is limited to SQL queries containing only characters which get past the function isspace(3). This effectively limits attacks to SQL commands like \"VACUUM\"."
        }, {
          "lang" : "en",
          "value" : "The DoS vulnerability exists because the is_eow() function in \"format.c\" does NOT just check the FIRST character of the supplied string for an End-Of-Word terminating character, but instead iterates over string and this way can skip a single embedded quotation mark. The is_repository_file() function then in turn assumes that the filename string can never contain a single quotation mark and traps into a SQL escaping problem."
        }, {
          "lang" : "en",
          "value" : "Successful remote unauthenticated exploit requires that CVSTrac is explicitly configured to allow anonymous users to add tickets (it is not by default)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cvstrac:cvstrac:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cvstrac:cvstrac:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cvstrac:cvstrac:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cvstrac:cvstrac:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cvstrac:cvstrac:1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cvstrac:cvstrac:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T20:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0348",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "interactual_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "interactual_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.60.12.0717",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "intervideo",
            "product" : {
              "product_data" : [ {
                "product_name" : "windvd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.27.172",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "roxio",
            "product" : {
              "product_data" : [ {
                "product_name" : "cineplayer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34314",
          "name" : "34314",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34315",
          "name" : "34315",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23032",
          "name" : "23032",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23075",
          "name" : "23075",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24556",
          "name" : "24556",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-37/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-37/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/922969",
          "name" : "VU#922969",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/463405/100/0/threaded",
          "name" : "20070321 Secunia Research: InterActual Player / CinePlayer IASystemInfo.dllActiveX Control Buffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23071",
          "name" : "23071",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1042",
          "name" : "ADV-2007-1042",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1043",
          "name" : "ADV-2007-1043",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33186",
          "name" : "interactual-iasysteminfo-bo(33186)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:interactual_technologies:interactual_player:2.60.12.0717:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intervideo:windvd:7.0.27.172:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:roxio:cineplayer:3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-21T19:19Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0349",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nicecoder",
            "product" : {
              "product_data" : [ {
                "product_name" : "indexu",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/45533",
          "name" : "45533",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457079/100/0/threaded",
          "name" : "20070116 vulnerability script indexu all versions",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31539",
          "name" : "indexu-upgrade-file-include(31539)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicecoder:indexu:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0350",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sme",
            "product" : {
              "product_data" : [ {
                "product_name" : "filemailer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.21",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2007-01/0395.html",
          "name" : "20070116 [x0n3-h4ck] SmE FileMailer 1.21 Remote Sql Injextion Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://attrition.org/pipermail/vim/2007-January/001244.html",
          "name" : "20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32833",
          "name" : "32833",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0221",
          "name" : "ADV-2007-0221",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31533",
          "name" : "smefilemailer-login-sql-injection(31533)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps, (2) us, (3) f, or (4) code parameter.  NOTE: the us vector in index.php is already covered by CVE-2007-0346."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sme:filemailer:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.21"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0351",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zonelabs",
            "product" : {
              "product_data" : [ {
                "product_name" : "zonealarm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/457167/100/0/threaded",
          "name" : "20070117 Windows logoff bug possible security vulnerability and exploit.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457217/100/0/threaded",
          "name" : "20070117 Re: Windows logoff bug possible security vulnerability and exploit.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457340/100/0/threaded",
          "name" : "20070118 Re: Windows logoff bug possible security vulnerability and exploit.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457807/100/200/threaded",
          "name" : "20070123 Re: Windows logoff bug possible security vulnerability and exploit.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459838/100/0/threaded",
          "name" : "20070211 Windows logoff bug solution possibly.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product.  The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:zonelabs:zonealarm:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.2
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 1.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0352",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "html_help_workshop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.02.0002",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31898",
          "name" : "31898",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23862",
          "name" : "23862",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2156",
          "name" : "2156",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017530",
          "name" : "1017530",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.anspi.pl/~porkythepig/visualization/cnt-expl1.cpp",
          "name" : "http://www.anspi.pl/~porkythepig/visualization/cnt-expl1.cpp",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457210/100/0/threaded",
          "name" : "20070117 Microsoft Help Workshop .CNT contents files buffer overflow vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22100",
          "name" : "22100",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31555",
          "name" : "ms-help-workshop-cnt-bo(31555)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3149",
          "name" : "3149",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:html_help_workshop:4.02.0002:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0353",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mywebland",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybloggie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0338.html",
          "name" : "20070117 [x0n3-h4ck] myBloggie 2.1.5 XSS exploit",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://mywebland.com/forums/showtopic.php?t=1224",
          "name" : "http://mywebland.com/forums/showtopic.php?t=1224",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32929",
          "name" : "32929",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32930",
          "name" : "32930",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2155",
          "name" : "2155",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017531",
          "name" : "1017531",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457206/100/0/threaded",
          "name" : "20070117 [x0n3-h4ck] myBloggie 2.1.5 XSS exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22097",
          "name" : "22097",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31554",
          "name" : "mybloggie-indexlogin-xss(31554)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mywebland:mybloggie:2.1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0354",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mgb",
            "product" : {
              "product_data" : [ {
                "product_name" : "opensource_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.4.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31612",
          "name" : "31612",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23825",
          "name" : "23825",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001246.html",
          "name" : "20070118 vendor ACK for MGB Guestbook issue",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22094",
          "name" : "22094",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.tv-kritik.net/mgb/index.php",
          "name" : "http://www.tv-kritik.net/mgb/index.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0232",
          "name" : "ADV-2007-0232",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31551",
          "name" : "mgb-email-sql-injection(31551)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3141",
          "name" : "3141",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mgb:opensource_guestbook:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.5.4.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0355",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "minimal_slp_service_agent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307430",
          "name" : "http://docs.info.apple.com/article.html?artnum=307430",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html",
          "name" : "APPLE-SA-2008-02-11",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-17-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-17-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23796",
          "name" : "23796",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017533",
          "name" : "1017533",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1019359",
          "name" : "1019359",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32693",
          "name" : "32693",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22101",
          "name" : "22101",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-043B.html",
          "name" : "TA08-043B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0239",
          "name" : "ADV-2007-0239",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31562",
          "name" : "macos-slpd-bo(31562)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3151",
          "name" : "3151",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with an invalid attr-list field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:minimal_slp_service_agent:10.4.11:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0356",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "common_controls_replacement_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "foldertreeview_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/22092",
          "name" : "22092",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31549",
          "name" : "ie-ccrp-dos(31549)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3142",
          "name" : "3142",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP.RootFolder property value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:common_controls_replacement_project:foldertreeview_activex_control:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:vista:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0357",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fritzdsl",
            "product" : {
              "product_data" : [ {
                "product_name" : "fritzdsl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "02.02.29",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051844.html",
          "name" : "20070117 Flaw in AVM UPNP service for windows",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32866",
          "name" : "32866",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23774",
          "name" : "23774",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2159",
          "name" : "2159",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22093",
          "name" : "22093",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0236",
          "name" : "ADV-2007-0236",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31556",
          "name" : "fritz-avm-directory-traversal(31556)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-encoded dot dot backslash) sequences in a URI requested from the AR7 webserver."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:fritzdsl:fritzdsl:02.02.29:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0358",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "jetdirect_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "x.20.nn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "x.21.nn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "x.22.nn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "x.23.nn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "x.24.nn",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00838612",
          "name" : "HPSBPI02185",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32867",
          "name" : "32867",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23802",
          "name" : "23802",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017532",
          "name" : "1017532",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22105",
          "name" : "22105",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0233",
          "name" : "ADV-2007-0233",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31589",
          "name" : "hp-jetdirect-unspecified-dos(31589)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the FTP server implementation in HP Jetdirect firmware x.20.nn through x.24.nn allows remote attackers to cause a denial of service via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:jetdirect_firmware:x.20.nn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:jetdirect_firmware:x.21.nn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:jetdirect_firmware:x.22.nn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:jetdirect_firmware:x.23.nn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:jetdirect_firmware:x.24.nn:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0359",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uberghey",
            "product" : {
              "product_data" : [ {
                "product_name" : "cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001247.html",
          "name" : "20070118 source verify: Uberghey CMS 0.3.1 RFI",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22098",
          "name" : "22098",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0230",
          "name" : "ADV-2007-0230",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31553",
          "name" : "uberghey-frontpage-file-include(31553)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3147",
          "name" : "3147",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uberghey:cms:0.3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0360",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oreon_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "oreon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.3_rc4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33711",
          "name" : "33711",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459811/100/0/threaded",
          "name" : "20070211 Oreon1.2.x Series Exploit Coded",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22107",
          "name" : "22107",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0229",
          "name" : "ADV-2007-0229",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31568",
          "name" : "oreon-index-file-include(31568)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3150",
          "name" : "3150",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oreon_project:oreon:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.3_rc4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0361",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "comscripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpmyphorum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/22099",
          "name" : "22099",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0231",
          "name" : "ADV-2007-0231",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31552",
          "name" : "phpmyphorum-frame-file-include(31552)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3145",
          "name" : "3145",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrary PHP code via a URL in the chem parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:comscripts:phpmyphorum:1.5a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0362",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freshreader",
            "product" : {
              "product_data" : [ {
                "product_name" : "freshreader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/jp/JVN%2395249468/index.html",
          "name" : "JVN#95249468",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://manual.freshreader.com/archives/2007/01/20070118_javasc.html",
          "name" : "http://manual.freshreader.com/archives/2007/01/20070118_javasc.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32923",
          "name" : "32923",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23806",
          "name" : "23806",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22106",
          "name" : "22106",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0241",
          "name" : "ADV-2007-0241",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31566",
          "name" : "freshreader-rssfeed-xss(31566)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the RSS feed component in FreshReader before 1.0.07010600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to tag attributes."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freshreader:freshreader:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0363",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openads",
            "product" : {
              "product_data" : [ {
                "product_name" : "openads",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.8_pr1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.9_pr1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23720",
          "name" : "23720",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=11386&release_id=479424",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=11386&release_id=479424",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=36679&release_id=479426",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=36679&release_id=479426",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22124",
          "name" : "22124",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0240",
          "name" : "ADV-2007-0240",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31570",
          "name" : "openads-unspecified-xss(31570)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in admin-search.php in (1) Openads for PostgreSQL (aka phpPgAds) before 2.0.10 and (2) Openads (aka phpAdsNew) before 2.0.10 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openads:openads:2.0.8_pr1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openads:openads:2.0.8_pr1:*:postgresql:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openads:openads:2.0.9_pr1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openads:openads:2.0.9_pr1:*:postgresql:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0364",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nicecoder",
            "product" : {
              "product_data" : [ {
                "product_name" : "indexu",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32839",
          "name" : "32839",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23764",
          "name" : "23764",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/32838",
          "name" : "32838",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32840",
          "name" : "32840",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32841",
          "name" : "32841",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32842",
          "name" : "32842",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32843",
          "name" : "32843",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32844",
          "name" : "32844",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32845",
          "name" : "32845",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32846",
          "name" : "32846",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32847",
          "name" : "32847",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32848",
          "name" : "32848",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32849",
          "name" : "32849",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32850",
          "name" : "32850",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32851",
          "name" : "32851",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457079/100/0/threaded",
          "name" : "20070116 vulnerability script indexu all versions",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22084",
          "name" : "22084",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0222",
          "name" : "ADV-2007-0222",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31538",
          "name" : "indexu-multiple-scripts-xss(31538)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to (a) suggest_category.php; the (2) u parameter to (b) user_detail.php; the (3) friend_name, (4) friend_email, (5) error_msg, (6) my_name, (7) my_email, and (8) id parameters to (c) tell_friend.php; the (9) error_msg, (10) email, (11) name, and (12) subject parameters to (d) sendmail.php; the (13) email, (14) error_msg, and (15) username parameters to (e) send_pwd.php; the (16) keyword parameter to (f) search.php; the (17) error_msg, (18) username, (19) password, (20) password2, and (21) email parameters to (g) register.php; the (22) url, (23) contact_name, and (24) email parameters to (h) power_search.php; the (25) path and (26) total parameters to (i) new.php; the (27) query parameter to (j) modify.php; the (28) error_msg parameter to (k) login.php; the (29) error_msg and (30) email parameters to (l) mailing_list.php; the (31) gateway parameter to (m) upgrade.php; and another unspecified vector."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicecoder:indexu:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicecoder:indexu:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicecoder:indexu:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-19T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0365",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nicola_asuni",
            "product" : {
              "product_data" : [ {
                "product_name" : "all_in_one_control_panel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.001",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.008",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.009",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32808",
          "name" : "32808",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23732",
          "name" : "23732",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=478370",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=478370",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0189",
          "name" : "ADV-2007-0189",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31486",
          "name" : "aiocp-unspecified-xss(31486)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.009 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this is probably a different vulnerability than CVE-2006-5830."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.001:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:1.3.008:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicola_asuni:all_in_one_control_panel:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3.009"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T19:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0366",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "maxum_development_corporation",
            "product" : {
              "product_data" : [ {
                "product_name" : "rumpus_ftp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32690",
          "name" : "32690",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-18-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-18-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23842",
          "name" : "23842",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31597",
          "name" : "rumpus-path-privilege-escalation(31597)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Untrusted search path vulnerability in Rumpus 5.1 and earlier allows local users to gain privileges via a modified PATH that points to a malicious ipfw program."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maxum_development_corporation:rumpus_ftp_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T21:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0367",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "maxum_development_corporation",
            "product" : {
              "product_data" : [ {
                "product_name" : "rumpus_ftp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32691",
          "name" : "32691",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-18-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-18-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23842",
          "name" : "23842",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Rumpus 5.1 and earlier has weak permissions for certain files and directories under /usr/local/Rumpus, including the configuration file, which allows local users to have an unknown impact by creating, modifying, or deleting files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maxum_development_corporation:rumpus_ftp_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T21:28Z",
    "lastModifiedDate" : "2008-11-15T06:40Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0368",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "michiel_broek",
            "product" : {
              "product_data" : [ {
                "product_name" : "mbse-bbs",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.33.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.33.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.33.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.33.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.35.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.70",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051859.html",
          "name" : "20070118 mbsebbs 0.70.0 & below local root exploit",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.mbse.eu/mbse/mbsebbs/index.html",
          "name" : "http://www.mbse.eu/mbse/mbsebbs/index.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22112",
          "name" : "22112",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31639",
          "name" : "mbsebbs-mbuseradd-bo(31639)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3154",
          "name" : "3154",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string in the MBSE_ROOT environment variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michiel_broek:mbse-bbs:0.33.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michiel_broek:mbse-bbs:0.33.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michiel_broek:mbse-bbs:0.33.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michiel_broek:mbse-bbs:0.33.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michiel_broek:mbse-bbs:0.35.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michiel_broek:mbse-bbs:0.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michiel_broek:mbse-bbs:0.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michiel_broek:mbse-bbs:0.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michiel_broek:mbse-bbs:0.70:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0369",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpbp",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpbp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "rc3_2.204",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34763",
          "name" : "34763",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31622",
          "name" : "phpbp-comment-sql-injection(31622)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3153",
          "name" : "3153",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands via the comment forum."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbp:phpbp:rc3_2.204:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0370",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpbp",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpbp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "rc3_2.204",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34762",
          "name" : "34762",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31619",
          "name" : "phpbp-banner-file-upload(31619)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3153",
          "name" : "3153",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in index.php in phpBP RC3 (2.204) and earlier allows remote administrators to inject arbitrary PHP code into an upload/banners/ file via a banners add operation that uploads the PHP code through an image_form parameter specifying a multiple-extension filename such as .jpg.vil.gif.php, which is stored in upload/banners/ under a different name, and executable via a direct request.  NOTE: a separate SQL injection issue could be leveraged to make this vulnerability reachable by remote unauthenticated attackers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbp:phpbp:rc3_2.204:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0371",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "common_controls_replacement_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "browsedialog_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34647",
          "name" : "34647",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22110",
          "name" : "22110",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3155",
          "name" : "3155",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP_BDc.SelectedFolder property value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:common_controls_replacement_project:browsedialog_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0372",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "francisco_burzi",
            "product" : {
              "product_data" : [ {
                "product_name" : "php-nuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33698",
          "name" : "33698",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33699",
          "name" : "33699",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33700",
          "name" : "33700",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33701",
          "name" : "33701",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33702",
          "name" : "33702",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459174/100/0/threaded",
          "name" : "20070204 Sql injection bugs in PHP-Nuke",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22116",
          "name" : "22116",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 7.9 allow remote attackers to execute arbitrary SQL commands via (1) the active parameter in admin/modules/modules.php; the (2) ad_class, (3) imageurl, (4) clickurl, (5) ad_code, or (6) position parameter in modules/Advertising/admin/index.php; or unspecified vectors in the (7) advertising, (8) weblinks, or (9) reviews section."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0373",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "joomla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/32527",
          "name" : "32527",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32528",
          "name" : "32528",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32529",
          "name" : "32529",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32530",
          "name" : "32530",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32531",
          "name" : "32531",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32532",
          "name" : "32532",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32533",
          "name" : "32533",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459203/100/0/threaded",
          "name" : "20070204 Sql injection bugs in Joomla and Mambo",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22122",
          "name" : "22122",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where parameter in (2) plugins/search/content.php or (3) plugins/search/weblinks.php; the text parameter in (4) plugins/search/contacts.php, (5) plugins/search/categories.php, or (6) plugins/search/sections.php; or (7) the email parameter in database/table/user.php, which is not properly handled by the check function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:1.5.0_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0374",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "joomla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "mambo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32520",
          "name" : "32520",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459203/100/0/threaded",
          "name" : "20070204 Sql injection bugs in Joomla and Mambo",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19734",
          "name" : "19734",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:1.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:1.5.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0375",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "joomla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32522",
          "name" : "32522",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32523",
          "name" : "32523",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32524",
          "name" : "32524",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32525",
          "name" : "32525",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32526",
          "name" : "32526",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459203/100/0/threaded",
          "name" : "20070204 Sql injection bugs in Joomla and Mambo",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php in plugins/authentication/; (5) modules/mod_mainmenu/menu.php; or other unspecified PHP scripts, which reveals the path in various error messages, related to a jimport function call at the beginning of each script."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:1.5.0_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0376",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "virtuemart",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtuemart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24058",
          "name" : "24058",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://virtuemart.svn.sourceforge.net/viewvc/*checkout*/virtuemart/branches/virtuemart-1_0_0/virtuemart/CHANGELOG.php?revision=607",
          "name" : "http://virtuemart.svn.sourceforge.net/viewvc/*checkout*/virtuemart/branches/virtuemart-1_0_0/virtuemart/CHANGELOG.php?revision=607",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459195/100/0/threaded",
          "name" : "20070204 Sql injection bugs in Virtuemart and Letterman",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22123",
          "name" : "22123",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Virtuemart 1.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtuemart:virtuemart:1.0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0377",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xoops",
            "product" : {
              "product_data" : [ {
                "product_name" : "xoops",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.16",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33684",
          "name" : "33684",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33685",
          "name" : "33685",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459150/100/0/threaded",
          "name" : "20070204 Sql injection bugs in Xoops 2.0.16 + Weblinks module",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22399",
          "name" : "22399",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in kernel/group.php in core, (2) the lid parameter in class/table_broken.php in the Weblinks module, and other unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xoops:xoops:2.0.16:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0378",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "docman",
            "product" : {
              "product_data" : [ {
                "product_name" : "docman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3_rc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/34650",
          "name" : "34650",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in DocMan 1.3 RC2 allow attackers to execute arbitrary SQL commands via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:docman:docman:1.3_rc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2008-11-13T06:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0379",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "docman",
            "product" : {
              "product_data" : [ {
                "product_name" : "docman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3_rc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/34651",
          "name" : "34651",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in DocMan 1.3 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:docman:docman:1.3_rc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2008-11-13T06:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0380",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "docman",
            "product" : {
              "product_data" : [ {
                "product_name" : "docman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3_rc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/34652",
          "name" : "34652",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "DocMan 1.3 RC2 allows remote attackers to obtain sensitive information (the full path) via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:docman:docman:1.3_rc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2008-11-13T06:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0381",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adaptive_technology_resource_centre",
            "product" : {
              "product_data" : [ {
                "product_name" : "atutor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/34660",
          "name" : "34660",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.atutor.ca/atutor/mantis/changelog_page.php",
          "name" : "http://www.atutor.ca/atutor/mantis/changelog_page.php",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.  NOTE: CVE analysis suggests that the vendor fixed these issues."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adaptive_technology_resource_centre:atutor:1.5.3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2008-11-13T06:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0382",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "letterman",
            "product" : {
              "product_data" : [ {
                "product_name" : "letterman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33688",
          "name" : "33688",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459195/100/0/threaded",
          "name" : "20070204 Sql injection bugs in Virtuemart and Letterman",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22117",
          "name" : "22117",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in letterman.class.php in the Letterman 1.2.3 (com_letterman) component for Joomla! before 1.0.12 allow remote attackers to execute arbitrary SQL commands via the id parameter, related to the (1) lm_sendMail, (2) saveNewsletter, and (3) cancelNewsletter functions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:letterman:letterman:1.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0383",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wdaemon",
            "product" : {
              "product_data" : [ {
                "product_name" : "wdaemon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/34661",
          "name" : "34661",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  WDaemon 9.5.4 allows remote attackers to access the /WorldClient.dll URI on TCP port 3000, which has unknown impact.  NOTE: The researcher reports that the vendor response was \"this is not a security bug.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wdaemon:wdaemon:7.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wdaemon:wdaemon:9.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wdaemon:wdaemon:9.5.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2008-11-13T06:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0384",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postnuke_software_foundation",
            "product" : {
              "product_data" : [ {
                "product_name" : "postnuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.764",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke",
          "name" : "http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35473",
          "name" : "35473",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22119",
          "name" : "22119",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.764:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2008-11-13T06:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0385",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postnuke_software_foundation",
            "product" : {
              "product_data" : [ {
                "product_name" : "postnuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.764",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke",
          "name" : "http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/FAQ/index.php?root=postnuke&r1=20350&r2=20911",
          "name" : "http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/FAQ/index.php?root=postnuke&r1=20350&r2=20911",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35472",
          "name" : "35472",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via \"unvalidated output\" in FAQ/index.php, possibly involving an undefined id_cat variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.764:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2008-11-13T06:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0386",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postnuke_software_foundation",
            "product" : {
              "product_data" : [ {
                "product_name" : "postnuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.764",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35471",
          "name" : "35471",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to \"an interesting bug.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.764:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2008-11-13T06:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0387",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "joomla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007-01-18",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html",
          "name" : "20070118 The vulnerabilities festival !",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34792",
          "name" : "34792",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackers.ir/advisories/festival.txt",
          "name" : "http://www.hackers.ir/advisories/festival.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459203/100/0/threaded",
          "name" : "20070204 Sql injection bugs in Joomla and Mambo",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:2007-01-18:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0388",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "woltlab",
            "product" : {
              "product_data" : [ {
                "product_name" : "burning_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "2.3.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33872",
          "name" : "33872",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31550",
          "name" : "wbb-search-sql-injection(31550)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3143",
          "name" : "3143",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3144",
          "name" : "3144",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0389",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "arsdigita",
            "product" : {
              "product_data" : [ {
                "product_name" : "arsdigita_community_education_solution",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "arsdigita_community_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.4.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33552",
          "name" : "33552",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457318/100/0/threaded",
          "name" : "20070118 Directory Traversal in ArsDigita Community System",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22121",
          "name" : "22121",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0286",
          "name" : "ADV-2007-0286",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31613",
          "name" : "acs-url-directory-traversal(31613)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allows remote attackers to read arbitrary files via .%252e/ (double-encoded dot dot slash) sequences in the URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:arsdigita:arsdigita_community_education_solution:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:arsdigita:arsdigita_community_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.4.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0390",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sabros.us",
            "product" : {
              "product_data" : [ {
                "product_name" : "sabros.us",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051868.html",
          "name" : "20070118 [x0n3-h4ck] sabros.us 1.7 XSS Exploit",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31602",
          "name" : "31602",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23824",
          "name" : "23824",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2170",
          "name" : "2170",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457331/100/0/threaded",
          "name" : "20070118 [x0n3-h4ck] sabros.us 1.7 XSS Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22115",
          "name" : "22115",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31600",
          "name" : "sabros-index-xss(31600)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in sabros.us 1.7 allows remote attackers to inject arbitrary web script or HTML via the tag parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sabros.us:sabros.us:1.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0391",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bitdefender",
            "product" : {
              "product_data" : [ {
                "product_name" : "bitdefender_client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "professional_plus_8.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051883.html",
          "name" : "20070119 Layered Defense Research Advisory: BitDefender Client 8.02 Format String Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.bitdefender.com/KB325-en--Format-string-vulnerability.html",
          "name" : "http://www.bitdefender.com/KB325-en--Format-string-vulnerability.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457414/100/0/threaded",
          "name" : "20070119 Layered Defense Research Advisory: BitDefender Client 8.02 Format String Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22128",
          "name" : "22128",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0253",
          "name" : "ADV-2007-0253",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31608",
          "name" : "bitdefender-scanjob-format-string(31608)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the log creation functionality of BitDefender Client Professional Plus 8.02 allows attackers to execute arbitrary code via certain scan job settings."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bitdefender:bitdefender_client:professional_plus_8.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0392",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/457279/100/0/threaded",
          "name" : "20070118 Multiple OS kernel insecure handling of stdio file descriptor",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457315/100/0/threaded",
          "name" : "20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0393",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/457279/100/0/threaded",
          "name" : "20070118 Multiple OS kernel insecure handling of stdio file descriptor",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457315/100/0/threaded",
          "name" : "20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Sun Solaris 9 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0394",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "hp-ux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/457279/100/0/threaded",
          "name" : "20070118 Multiple OS kernel insecure handling of stdio file descriptor",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457315/100/0/threaded",
          "name" : "20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "HP HP-UX B11.11 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0395",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "comvironment",
            "product" : {
              "product_data" : [ {
                "product_name" : "comvironment",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34621",
          "name" : "34621",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22108",
          "name" : "22108",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0266",
          "name" : "ADV-2007-0266",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31564",
          "name" : "comvironment-grabglobals-file-include(31564)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3152",
          "name" : "3152",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:comvironment:comvironment:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0396",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "hp-ux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.23",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00837319",
          "name" : "SSRT061289",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32869",
          "name" : "32869",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23800",
          "name" : "23800",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017527",
          "name" : "1017527",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22103",
          "name" : "22103",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0234",
          "name" : "ADV-2007-0234",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31565",
          "name" : "hp-ipfilter-dos(31565)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6104",
          "name" : "oval:org.mitre.oval:def:6104",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.23:*:ia64_64-bit:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-19T23:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0397",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "adaptive_security_appliance_device_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2.53",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "security_monitoring_analysis_and_response_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32720",
          "name" : "32720",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23836",
          "name" : "23836",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017535",
          "name" : "1017535",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017536",
          "name" : "1017536",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a00807c517f.shtml",
          "name" : "20070118 SSL/TLS Certificate and SSH Public Key Validation Vulnerability",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22111",
          "name" : "22111",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0245",
          "name" : "ADV-2007-0245",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31567",
          "name" : "cisco-csmars-asdm-device-spoofing(31567)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those devices to obtain sensitive information or generate incorrect information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:security_monitoring_analysis_and_response_system:4.2.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:adaptive_security_appliance_device_manager:5.2.53:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-20T01:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0398",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "arnotic",
            "product" : {
              "product_data" : [ {
                "product_name" : "a-forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001249.html",
          "name" : "20070122 a-forum xss - who? what? where?",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457503/100/0/threaded",
          "name" : "20070119 a-forum xss",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31610",
          "name" : "aforum-unspecified-xss(31610)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in forum.php3 in Arnaud Guyonne (aka Arnotic) a-forum allow remote attackers to inject arbitrary web script or HTML via the (1) Sujet or (2) Pseudo field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:arnotic:a-forum:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-22T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0399",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "simple_machines",
            "product" : {
              "product_data" : [ {
                "product_name" : "simple_machines_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1_rc3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aria-security.com/forum/showthread.php?p=128",
          "name" : "http://aria-security.com/forum/showthread.php?p=128",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32606",
          "name" : "32606",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2169",
          "name" : "2169",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457508/100/0/threaded",
          "name" : "20070120 SMF \"index.php?action=pm\" Cross Site-Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457627/100/0/threaded",
          "name" : "20070121 Re: SMF \"index.php?action=pm\" Cross Site-Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457761/100/200/threaded",
          "name" : "20070122 Re: Re: Re: SMF \"index.php?action=pm\" Cross Site-Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458194/100/100/threaded",
          "name" : "20070126 Re: Re: Re: Re: SMF \"index.php?action=pm\" Cross Site-Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458904/100/0/threaded",
          "name" : "20070202 Re: SMF \"index.php?action=pm\" Cross Site-Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22143",
          "name" : "22143",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31612",
          "name" : "smf-pm-xss(31612)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:simple_machines:simple_machines_forum:1.1_rc3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-22T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0400",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "easebay_resources",
            "product" : {
              "product_data" : [ {
                "product_name" : "login_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2167",
          "name" : "2167",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457505/100/0/threaded",
          "name" : "20070120 Login Manager Multiple HTML Injections",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31614",
          "name" : "loginmanager-memberlist-xss(31614)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:easebay_resources:login_manager:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-22T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0401",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "easebay_resources",
            "product" : {
              "product_data" : [ {
                "product_name" : "login_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2167",
          "name" : "2167",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457505/100/0/threaded",
          "name" : "20070120 Login Manager Multiple HTML Injections",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the init_row parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:easebay_resources:login_manager:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-22T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0402",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "easebay_resources",
            "product" : {
              "product_data" : [ {
                "product_name" : "paypal_subscription_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33559",
          "name" : "33559",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2168",
          "name" : "2168",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457506/100/0/threaded",
          "name" : "20070120 Paypal Subscription Manager Multiple HTML Injections",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31618",
          "name" : "psm-editmember-xss(31618)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in admin/edit_member.php in Easebay Resources Paypal Subscription Manager allows remote attackers to inject arbitrary web script or HTML via the username parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:easebay_resources:paypal_subscription_manager:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-22T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0403",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "easebay_resources",
            "product" : {
              "product_data" : [ {
                "product_name" : "paypal_subscription_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33560",
          "name" : "33560",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/36103",
          "name" : "36103",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2168",
          "name" : "2168",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457506/100/0/threaded",
          "name" : "20070120 Paypal Subscription Manager Multiple HTML Injections",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31616",
          "name" : "psm-memberlist-sql-injection(31616)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in admin/memberlist.php in Easebay Resources Paypal Subscription Manager allows remote attackers to execute arbitrary SQL commands via the keyword parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:easebay_resources:paypal_subscription_manager:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-22T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0404",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "django_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "django",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.95",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://code.djangoproject.com/changeset/3592",
          "name" : "http://code.djangoproject.com/changeset/3592",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23826",
          "name" : "23826",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22134",
          "name" : "22134",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31627",
          "name" : "django-po-code-execution(31627)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:django_project:django:0.95:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0405",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "django_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "django",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.95",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://code.djangoproject.com/changeset/3754",
          "name" : "http://code.djangoproject.com/changeset/3754",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23826",
          "name" : "23826",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22138",
          "name" : "22138",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31628",
          "name" : "django-request-session-hijacking(31628)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different user."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:django_project:django:0.95:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0406",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gxine",
            "product" : {
              "product_data" : [ {
                "product_name" : "gxine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/38320",
          "name" : "38320",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/38321",
          "name" : "38321",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=9655&release_id=476891",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=9655&release_id=476891",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0259",
          "name" : "ADV-2007-0259",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://xinehq.de/index.php/news?show_category_id=1",
          "name" : "http://xinehq.de/index.php/news?show_category_id=1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31604",
          "name" : "gxine-serversetup-serverclient-bo(31604)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in the (1) main function in (a) client.c, and the (2) server_setup and (3) server_client_connect functions in (b) server.c in gxine 0.5.9 and earlier allow local users to cause a denial of service (daemon crash) or gain privileges via a long HOME environment variable.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gxine:gxine:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.5.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0407",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "plain_black",
            "product" : {
              "product_data" : [ {
                "product_name" : "webgui",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.4_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32928",
          "name" : "32928",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23754",
          "name" : "23754",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.plainblack.com/bugs/tracker/security-update-cross-site-scripting-vulnerability",
          "name" : "http://www.plainblack.com/bugs/tracker/security-update-cross-site-scripting-vulnerability",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.plainblack.com/downloads/builds/7.3.5-beta/WebGUI/docs/changelog/7.x.x.txt",
          "name" : "http://www.plainblack.com/downloads/builds/7.3.5-beta/WebGUI/docs/changelog/7.x.x.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22114",
          "name" : "22114",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0242",
          "name" : "ADV-2007-0242",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31573",
          "name" : "webgui-username-xss(31573)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Operation/User.pm in Plain Black WebGUI before 7.3.5 (beta) allows remote attackers to inject arbitrary web script or HTML via the username parameter during anonymous registration, a different vector than CVE-2007-0308.  NOTE: it is possible that a separate \"WikiPage titles\" issue was also fixed."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:7.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:7.3.4_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0408",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/202",
          "name" : "BEA07-135.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38500",
          "name" : "38500",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017519",
          "name" : "1017519",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, which allows remote attackers to obtain access via an untrusted X.509 certificate."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp4:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0409",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/203",
          "name" : "BEA07-136.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38501",
          "name" : "38501",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp6:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp4:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:S/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 2.7,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0410",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/204",
          "name" : "BEA07-137.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38502",
          "name" : "38502",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the thread management in BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1, when T3 authentication is used, allows remote attackers to cause a denial of service (thread and system hang) via unspecified \"sequences of events.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2018-10-17T19:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0411",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/205",
          "name" : "BEA07-138.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38503",
          "name" : "38503",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp5:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:ga:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0412",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/206",
          "name" : "BEA07-139.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38505",
          "name" : "38505",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read arbitrary files inside the class-path property via .ear or exploded .ear files that use the manifest class-path property to point to utility jar files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2018-10-17T19:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0413",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/207",
          "name" : "BEA07-140.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38504",
          "name" : "38504",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server 8.1 through 8.1 SP5 stores cleartext data in a backup of config.xml after offline editing, which allows local users to obtain sensitive information by reading this backup file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp5:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0414",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/208",
          "name" : "BEA07-141.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38506",
          "name" : "38506",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (server hang) via certain requests that cause muxer threads to block when processing error pages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp7:*:*:*:*:*:*",
          "versionEndIncluding" : "6.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp6:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp5:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0415",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/209",
          "name" : "BEA07-142.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38509",
          "name" : "38509",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp5:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0416",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/210",
          "name" : "BEA07-143.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38510",
          "name" : "38510",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows remote attackers to bypass application security."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0417",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/211",
          "name" : "BEA07-144.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38511",
          "name" : "38511",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp7:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0418",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/212",
          "name" : "BEA07-145.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38512",
          "name" : "38512",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp6:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp5:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0419",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/213",
          "name" : "BEA07-146.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38513",
          "name" : "38513",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0420",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/214",
          "name" : "BEA07-147.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38514",
          "name" : "38514",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server 9.0, 9.1, and 9.2 Gold allows remote attackers to obtain sensitive information via malformed HTTP requests, which reveal data from previous requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:ga:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0421",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/215",
          "name" : "BEA07-148.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32859",
          "name" : "32859",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server 6.1 through 6.1 SP7, and 7.0 through 7.0 SP7 allows remote attackers to cause a denial of service (disk consumption) via requests containing malformed headers, which cause a large amount of data to be written to the server log."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp7:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2018-10-17T19:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0422",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/217",
          "name" : "BEA07-150.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32858",
          "name" : "32858",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server 9.0, 9.1, and 9.2 Gold, when running on Solaris 9, allows remote attackers to cause a denial of service (server inaccessibility) via manipulated socket connections."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.2:ga:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0423",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/218",
          "name" : "BEA07-151.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32857",
          "name" : "32857",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017521",
          "name" : "1017521",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be \"inadvertently affected,\" which has an unknown impact."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0424",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/219",
          "name" : "BEA07-152.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32856",
          "name" : "32856",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the BEA WebLogic Server proxy plug-in for Netscape Enterprise Server before September 2006 for Netscape Enterprise Server allow remote attackers to cause a denial of service via certain requests that trigger errors that lead to a server being marked as unavailable, hosting web server failure, or CPU consumption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0425",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "jrockit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.2",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/222",
          "name" : "BEA07-155.00",
          "refsource" : "BEA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/38515",
          "name" : "38515",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017525",
          "name" : "1017525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in BEA WebLogic Platform and Server 8.1 through 8.1 SP5, and JRockit 1.4.2 R4.5 and earlier, allows attackers to gain privileges via unspecified vectors, related to an \"overflow condition,\" probably a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:jrockit:*:r24.5:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:*:sp5:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0426",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/223",
          "name" : "BEA07-156.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32854",
          "name" : "32854",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/38516",
          "name" : "38516",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23750",
          "name" : "23750",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017521",
          "name" : "1017521",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0213",
          "name" : "ADV-2007-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allow attackers to bypass intended restrictions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0427",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "html_help_workshop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.03.0002",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31899",
          "name" : "31899",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23862",
          "name" : "23862",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2177",
          "name" : "2177",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.anspi.pl/~porkythepig/visualization/hpj-x01.cpp",
          "name" : "http://www.anspi.pl/~porkythepig/visualization/hpj-x01.cpp",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457436/100/0/threaded",
          "name" : "20070119 Help project files (.HPJ) buffer overflow vulnerability in Microsoft Help Workshop",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22135",
          "name" : "22135",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:html_help_workshop:4.03.0002:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-23T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0428",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wzdftpd",
            "product" : {
              "product_data" : [ {
                "product_name" : "wzdftpd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051896.html",
          "name" : "20070119 WzdFTPD < 8.1 Denial of service",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32941",
          "name" : "32941",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23852",
          "name" : "23852",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2171",
          "name" : "2171",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017537",
          "name" : "1017537",
          "refsource" : "SECTRACK",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.s21sec.com/avisos/s21sec-033-en.txt",
          "name" : "http://www.s21sec.com/avisos/s21sec-033-en.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457454/100/0/threaded",
          "name" : "20070119 WzdFTPD < 8.1 Denial of service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0277",
          "name" : "ADV-2007-0277",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31599",
          "name" : "wzdftpd-ftp-dos(31599)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the chtbl_lookup function in hash.c for WzdFTPD 8.0 and earlier allows remote attackers to cause a denial of service via a crafted FTP command, probably due to a NULL pointer dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wzdftpd:wzdftpd:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0429",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "divx",
            "product" : {
              "product_data" : [ {
                "product_name" : "divx_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/37693",
          "name" : "37693",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22133",
          "name" : "22133",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31601",
          "name" : "divx-divxbrowserplugin-dos(31601)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3157",
          "name" : "3157",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the GoWindowed method for a certain instance of the ActiveX object."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:divx:divx_player:6.4.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0430",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://risesecurity.org/advisory.php?id=RISE-2007001.txt",
          "name" : "http://risesecurity.org/advisory.php?id=RISE-2007001.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23823",
          "name" : "23823",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2178",
          "name" : "2178",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017538",
          "name" : "1017538",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32942",
          "name" : "32942",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457466/100/0/threaded",
          "name" : "20070119 [RISE-2007001] Apple Mac OS X 10.4.x kernel shared_region_map_file_np() memory corruption vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0275",
          "name" : "ADV-2007-0275",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31645",
          "name" : "macos-sharedregionmapfilenp-dos(31645)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "10.4.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0431",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "avm",
            "product" : {
              "product_data" : [ {
                "product_name" : "fritzbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7050",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.avm.de/fritz.box/fritzbox.fon_wlan_7050/firmware/info.txt",
          "name" : "ftp://ftp.avm.de/fritz.box/fritzbox.fon_wlan_7050/firmware/info.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0387.html",
          "name" : "20070119 DoS against AVM Fritz!Box 7050 (and others)",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://mazzoo.de/blog/2007/01/18#FritzBox_DoS",
          "name" : "http://mazzoo.de/blog/2007/01/18#FritzBox_DoS",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32940",
          "name" : "32940",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23868",
          "name" : "23868",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457406/100/0/threaded",
          "name" : "20070119 DoS against AVM Fritz!Box 7050 (and others)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457829/100/0/threaded",
          "name" : "20070123 Re: DoS against AVM Fritz!Box 7050 (and others)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22130",
          "name" : "22130",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0272",
          "name" : "ADV-2007-0272",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31633",
          "name" : "fritzbox-udp-packet-dos(31633)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application crash) via a zero-length UDP packet to the SIP port (port 5060)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:avm:fritzbox:7050:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0432",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "aqualogic_service_bus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/224",
          "name" : "BEA07-157.00",
          "refsource" : "BEA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32862",
          "name" : "32862",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23786",
          "name" : "23786",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017523",
          "name" : "1017523",
          "refsource" : "SECTRACK",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_service_bus:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_service_bus:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_service_bus:2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T02:28Z",
    "lastModifiedDate" : "2008-11-13T06:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0433",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "aqualogic_service_bus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/221",
          "name" : "BEA07-154.00",
          "refsource" : "BEA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32861",
          "name" : "32861",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23786",
          "name" : "23786",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017524",
          "name" : "1017524",
          "refsource" : "SECTRACK",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_service_bus:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_service_bus:2.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_service_bus:2.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_service_bus:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_service_bus:2.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_service_bus:2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T02:28Z",
    "lastModifiedDate" : "2008-11-13T06:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0434",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "aqualogic_enterprise_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/220",
          "name" : "BEA07-153.00",
          "refsource" : "BEA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32860",
          "name" : "32860",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23786",
          "name" : "23786",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22082",
          "name" : "22082",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_enterprise_security:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_enterprise_security:2.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_enterprise_security:2.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_enterprise_security:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_enterprise_security:2.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:aqualogic_enterprise_security:2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T02:28Z",
    "lastModifiedDate" : "2008-11-13T06:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0435",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "t-com",
            "product" : {
              "product_data" : [ {
                "product_name" : "speedport_500v",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "speedport_500v_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.31",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32995",
          "name" : "32995",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23853",
          "name" : "23853",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457453/100/0/threaded",
          "name" : "20070119 Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457645/100/0/threaded",
          "name" : "20070121 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457656/100/0/threaded",
          "name" : "20070122 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460319/100/0/threaded",
          "name" : "20070216 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22160",
          "name" : "22160",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31621",
          "name" : "tcom-login-authentication-bypass(31621)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cookie value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:h:t-com:speedport_500v:-:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:t-com:speedport_500v_firmware:1.31:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0436",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "barron_mccann",
            "product" : {
              "product_data" : [ {
                "product_name" : "install",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "bms1472",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "x-kryptor_driver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "bms1446hrr",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "x-kryptor_secure_client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "xgntr",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "bms1351",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/niscc/NISCC-462660/index.html",
          "name" : "http://jvn.jp/niscc/NISCC-462660/index.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33110",
          "name" : "33110",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24045",
          "name" : "24045",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&S2ID=14",
          "name" : "http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&S2ID=14",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.bemacpromotions.com/files/xkpatch462660.zip",
          "name" : "http://www.bemacpromotions.com/files/xkpatch462660.zip",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml",
          "name" : "http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml",
          "name" : "http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22424",
          "name" : "22424",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0496",
          "name" : "ADV-2007-0496",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via interactive use of Explorer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:barron_mccann:install:bms1472:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:barron_mccann:x-kryptor_driver:bms1446hrr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:barron_mccann:x-kryptor_secure_client:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:barron_mccann:xgntr:bms1351:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-04T00:28Z",
    "lastModifiedDate" : "2011-05-18T04:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0437",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "intersystems",
            "product" : {
              "product_data" : [ {
                "product_name" : "cache_database",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.cpni.gov.uk/Products/alerts/2928.aspx",
          "name" : "http://www.cpni.gov.uk/Products/alerts/2928.aspx",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.mwrinfosecurity.com/advisories/mwri_cache-sample-files-xss-advisory_2007-04-04.pdf",
          "name" : "http://www.mwrinfosecurity.com/advisories/mwri_cache-sample-files-xss-advisory_2007-04-04.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.mwrinfosecurity.com/news/1658.html",
          "name" : "http://www.mwrinfosecurity.com/news/1658.html",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attackers to inject arbitrary web script or HTML via (1) the TO parameter to loop.csp, (2) the VALUE parameter to cookie.csp, and (3) the PAGE parameter to showsource.csp in csp/samples/; and allow remote authenticated users to inject arbitrary web script or HTML via (4) the ERROR parameter to csp/samples/xmlclasseserror.csp, and unspecified vectors in (5) object.csp and (6) lotteryhistory.csp in csp/samples/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intersystems:cache_database:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-08-20T18:17Z",
    "lastModifiedDate" : "2008-09-05T21:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0441",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "openview_network_node_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.50",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32728",
          "name" : "32728",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017504",
          "name" : "1017504",
          "refsource" : "SECTRACK",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456623/100/100/threaded",
          "name" : "SSRT05103",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0153",
          "name" : "ADV-2007-0153",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to execute arbitrary commands via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:6.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_network_node_manager:7.50:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T16:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0442",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "os_400",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r530",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r535",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32812",
          "name" : "32812",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23765",
          "name" : "23765",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=nas204b3e62c8a63af708625718e0043eddc",
          "name" : "MA33861",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=nas2c8623b2ed01d45d08625718e0043edc2",
          "name" : "MA33860",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an \"Integrity Problem\" involving LIC-TCPIP and TCP reset.  NOTE: it is possible that this issue is related to CVE-2004-0230, but this is not certain."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:os_400:r530:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:os_400:r535:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T16:28Z",
    "lastModifiedDate" : "2008-11-15T06:40Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0443",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gracenote",
            "product" : {
              "product_data" : [ {
                "product_name" : "cddbcontrol_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34327",
          "name" : "34327",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22924",
          "name" : "22924",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0",
          "name" : "http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/466403/100/0/threaded",
          "name" : "20070420 ZDI-07-021: GraceNote CDDBControl ActiveX Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23567",
          "name" : "23567",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017937",
          "name" : "1017937",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1475",
          "name" : "ADV-2007-1475",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-021.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-021.html",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33773",
          "name" : "cddbcontrol-activex-bo(33773)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in the CDDBControl ActiveX control in Gracenote CDDB before 20070418 allow remote attackers to execute arbitrary code via long values for certain Proxy configuration parameters."
        }, {
          "lang" : "en",
          "value" : "The vendor has address this issue with the following information: http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gracenote:cddbcontrol_activex_control:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-04-24T16:19Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0444",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "citrix",
            "product" : {
              "product_data" : [ {
                "product_name" : "metaframe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "metaframe_presentation_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32958",
          "name" : "32958",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23869",
          "name" : "23869",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017553",
          "name" : "1017553",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.citrix.com/article/CTX111686",
          "name" : "http://support.citrix.com/article/CTX111686",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458002/100/0/threaded",
          "name" : "20070124 ZDI-07-006: Citrix Metaframe Presentation Server Print Provider Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22217",
          "name" : "22217",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c",
          "name" : "http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0328",
          "name" : "ADV-2007-0328",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-006.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-006.html",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the (1) EnumPrintersW and (2) OpenPrinter functions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:citrix:metaframe:1.0:*:xp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:citrix:metaframe_presentation_server:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:citrix:metaframe_presentation_server:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-24T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0445",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kaspersky_lab",
            "product" : {
              "product_data" : [ {
                "product_name" : "kaspersky_anti-virus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "kaspersky_internet_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24778",
          "name" : "24778",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kaspersky.com/technews?id=203038693",
          "name" : "http://www.kaspersky.com/technews?id=203038693",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kaspersky.com/technews?id=203038694",
          "name" : "http://www.kaspersky.com/technews?id=203038694",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464878/100/0/threaded",
          "name" : "20070405 ZDI-07-013: Kaspersky AntiVirus Engine ARJ Archive Parsing Heap Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23346",
          "name" : "23346",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017882",
          "name" : "1017882",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017883",
          "name" : "1017883",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1268",
          "name" : "ADV-2007-1268",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-013.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-013.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33489",
          "name" : "kaspersky-arj-bo(33489)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the arj.ppl module in the OnDemand Scanner in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to execute arbitrary code via crafted ARJ archives."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kaspersky_lab:kaspersky_anti-virus:6.0:*:file_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kaspersky_lab:kaspersky_anti-virus:6.0:*:windows_workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kaspersky_lab:kaspersky_anti-virus:6.0:*:workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kaspersky_lab:kaspersky_internet_security:*:maintenance_pack_2:*:*:*:*:*:*",
          "versionEndIncluding" : "6.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-06T00:19Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0446",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "mercury_loadrunner_agent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mercury_monitor_over_firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mercury_performance_center_agent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00854250",
          "name" : "HPSBGN02187",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33132",
          "name" : "33132",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24112",
          "name" : "24112",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017611",
          "name" : "1017611",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017612",
          "name" : "1017612",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017613",
          "name" : "1017613",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ciac.org/ciac/bulletins/r-123.shtml",
          "name" : "R-123",
          "refsource" : "CIAC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/303012",
          "name" : "VU#303012",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459505/100/0/threaded",
          "name" : "20070208 ZDI-07-007: HP Mercury LoadRunner Agent Stack Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22487",
          "name" : "22487",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0535",
          "name" : "ADV-2007-0535",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-007.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-007.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32390",
          "name" : "mercury-multiple-agent-bo(32390)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in mchan.dll."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:mercury_loadrunner_agent:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:mercury_loadrunner_agent:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:mercury_monitor_over_firewall:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:mercury_performance_center_agent:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:mercury_performance_center_agent:8.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0447",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "antivirus_scan_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.7.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.8.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "brightmail_antispam",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "client_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1_build_9.0.1.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2_build_9.0.2.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3_build_9.0.3.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5_build_1100_mp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.359",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.1001",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.1007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.1008",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2.2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2.2001",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2.2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2.2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2.2011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2.2020",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2.2021",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.394",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.396",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.400",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.401",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mail_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.4.743",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5_build_719",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5_build_736",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5_build_741",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1.107",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6_build_97",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.204",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "norton_antivirus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.338",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.1.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.3.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.5.1100",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.6.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0.359",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1.1007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1.1008",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.2001",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.2011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.2020",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.2021",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4.4010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.394",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.396",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.400",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.401",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "norton_internet_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "norton_personal_firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006_9.1.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006_9.1.1.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "norton_system_works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "symantec_antivirus_filtering_+for_domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.12",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "web_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.70",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.76",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1_build_3.01.70",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1_build_3.01.72",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1_build_3.01.74",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.63",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.67",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.68",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "gateway_security_5000_series",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "gateway_security_5400",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mail_security_8820_appliance",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36118",
          "name" : "36118",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26053",
          "name" : "26053",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11f.html",
          "name" : "http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11f.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24282",
          "name" : "24282",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2508",
          "name" : "ADV-2007-2508",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-040.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-040.html",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.0:*:clearswift:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3:*:caching:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3:*:clearswift:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3:*:microsoft_sharepoint:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3:*:network_attached_storage:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3.7.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3.8.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3.12:*:caching:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3.12:*:clearswift:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3.12:*:messaging:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3.12:*:microsoft_sharepoint:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:4.3.12:*:network_attached_storage:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:brightmail_antispam:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:brightmail_antispam:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:brightmail_antispam:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:brightmail_antispam:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:brightmail_antispam:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:brightmail_antispam:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:brightmail_antispam:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:2.0:*:scf_7.1:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:2.0:build_9.0.0.338:stm:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:2.0.1_build_9.0.1.1000:mr1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:2.0.2_build_9.0.2.1000:mr2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:2.0.3_build_9.0.3.1000:mr3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:2.0.4:mr4_build1000:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:2.0.5_build_1100_mp1:mr5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:2.0.6:mr6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0.0.359:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0.1.1000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0.1.1001:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0.1.1007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0.1.1008:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0.2.2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0.2.2001:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0.2.2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0.2.2010:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0.2.2011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0.2.2020:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.0.2.2021:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.1.394:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.1.396:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.1.400:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:client_security:3.1.401:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.0:*:domino:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.0:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.0:build456:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.0:build463:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.0:build465:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.0:build736:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.0:build741:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.0:build743:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.0.1:*:domino:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.1:build458:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.1:build459:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.1:build461:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.5:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.5.4.743:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.5_build_719:*:exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.5_build_736:*:exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.5_build_741:*:exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.6.1.107:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.6.3:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:4.6_build_97:*:exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:5.0:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:5.0:*:smtp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:5.0.0.204:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:5.0.1:*:smtp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:5.1.0:*:domino:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:mail_security:6.0.0:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:*:*:corporate_edition_for_linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0:*:macintosh:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.0:*:macintosh:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.0.338:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.1:*:macintosh:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.1.1.1000:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.2:*:macintosh:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.2.1000:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.3:*:macintosh:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.3.1000:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.4:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.4:mr4_build_1000:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.5:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.5.1100:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:9.0.6.1000:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0:*:macintosh:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.0:*:macintosh:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.0.359:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.1:*:macintosh:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.1.1000:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.1.1007:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.1.1008:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.2.2000:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.2.2001:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.2.2002:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.2.2010:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.2.2011:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.2.2020:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.0.2.2021:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.1:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.1.4:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.1.4:mr4_mp1_build4010:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.1.4.4010:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.1.394:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.1.396:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.1.400:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.1.401:*:corporate_edition:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:10.9.1:*:macintosh:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2004:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2005:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2005:11.0:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2005:11.0.9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_antivirus:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:3.0:*:macintosh:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2004:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2005:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2005:11.0:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2005:11.0.9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2005:11.5.6.14:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_internet_security:2006:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_personal_firewall:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_personal_firewall:2006_9.1.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_personal_firewall:2006_9.1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:3.0:*:macintosh:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2005:*:premier:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2005:11.0:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2005:11.0.9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:symantec_antivirus_filtering_\\+for_domino:3.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.0.1.70:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.0.1.76:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.0.1_build_3.01.70:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.0.1_build_3.01.72:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.0.1_build_3.01.74:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.59:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.63:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.67:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.68:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:5.0:*:microsoft_isa_2004:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:symantec:gateway_security_5000_series:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:symantec:gateway_security_5400:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:symantec:mail_security_8820_appliance:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-10-05T21:17Z",
    "lastModifiedDate" : "2012-10-31T02:28Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0448",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/achievement_securityalert/44",
          "name" : "20070125 PHP 5.2.0 safe_mode bypass (by Writing Mode)",
          "refsource" : "SREASONRES",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2175",
          "name" : "2175",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22261",
          "name" : "22261",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-24T18:30Z",
    "lastModifiedDate" : "2008-09-11T00:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0449",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ca",
            "product" : {
              "product_data" : [ {
                "product_name" : "brightstor_arcserve_backup_laptops_desktops",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "brightstor_mobile_backup",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r4.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "business_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "desktop_management_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "desktop_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23897",
          "name" : "23897",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017548",
          "name" : "1017548",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp",
          "name" : "http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/357308",
          "name" : "VU#357308",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/611276",
          "name" : "VU#611276",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/31593",
          "name" : "31593",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457945/30/8460/threaded",
          "name" : "20070124 [CAID 34993]: CA BrightStor ARCserve Backup for Laptops and Desktops Multiple Overflow Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458644/100/0/threaded",
          "name" : "20070131 Remote Unauthenticated Code Execution CA BrightStor ARCserve Backup",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458648/100/0/threaded",
          "name" : "20070131 Remote Unauthenticated Code Execution II CA BrightStor ARCserve Backup for Laptops & Desktops",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22199",
          "name" : "22199",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22340",
          "name" : "22340",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22342",
          "name" : "22342",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0314",
          "name" : "ADV-2007-0314",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97696",
          "name" : "http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97696",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=34993",
          "name" : "http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=34993",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31704",
          "name" : "ca-multiple-unspecified-bo(31704)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote attackers to execute arbitrary code via crafted packets to TCP port (1) 1900 or (2) 2200."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_mobile_backup:r4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:business_protection_suite:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:desktop_management_suite:11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:desktop_management_suite:11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:desktop_protection_suite:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-23T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0450",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "tomcat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx",
          "name" : "http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=306172",
          "name" : "http://docs.info.apple.com/article.html?artnum=306172",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795",
          "name" : "SSRT071447",
          "refsource" : "HP",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html",
          "name" : "APPLE-SA-2007-07-31",
          "refsource" : "APPLE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.vmware.com/pipermail/security-announce/2008/000003.html",
          "name" : "[Security-announce] 20080107 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1",
          "refsource" : "MLIST",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24732",
          "name" : "24732",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25106",
          "name" : "25106",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25280",
          "name" : "25280",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26235",
          "name" : "26235",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26660",
          "name" : "26660",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/27037",
          "name" : "27037",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28365",
          "name" : "28365",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30899",
          "name" : "30899",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/30908",
          "name" : "30908",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/33668",
          "name" : "33668",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200705-03.xml",
          "name" : "GLSA-200705-03",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2446",
          "name" : "2446",
          "refsource" : "SREASON",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1",
          "name" : "239312",
          "refsource" : "SUNALERT",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540",
          "name" : "http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link", "Third Party Advisory" ]
        }, {
          "url" : "http://tomcat.apache.org/security-4.html",
          "name" : "http://tomcat.apache.org/security-4.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tomcat.apache.org/security-5.html",
          "name" : "http://tomcat.apache.org/security-5.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tomcat.apache.org/security-6.html",
          "name" : "http://tomcat.apache.org/security-6.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.fujitsu.com/global/support/software/security/products-f/interstage-200702e.html",
          "name" : "http://www.fujitsu.com/global/support/software/security/products-f/interstage-200702e.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:241",
          "name" : "MDKSA-2007:241",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_15_sr.html",
          "name" : "SUSE-SR:2007:015",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_5_sr.html",
          "name" : "SUSE-SR:2007:005",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0327.html",
          "name" : "RHSA-2007:0327",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0360.html",
          "name" : "RHSA-2007:0360",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0261.html",
          "name" : "RHSA-2008:0261",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.sec-consult.com/287.html",
          "name" : "http://www.sec-consult.com/287.html",
          "refsource" : "MISC",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.sec-consult.com/fileadmin/Advisories/20070314-0-apache_tomcat_directory_traversal.txt",
          "name" : "http://www.sec-consult.com/fileadmin/Advisories/20070314-0-apache_tomcat_directory_traversal.txt",
          "refsource" : "MISC",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/462791/100/0/threaded",
          "name" : "20070314 SEC Consult SA-20070314-0 :: Apache HTTP Server / Tomcat directory traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/485938/100/0/threaded",
          "name" : "20080108 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/500396/100/0/threaded",
          "name" : "20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/500412/100/0/threaded",
          "name" : "20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22960",
          "name" : "22960",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25159",
          "name" : "25159",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0975",
          "name" : "ADV-2007-0975",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2732",
          "name" : "ADV-2007-2732",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/3087",
          "name" : "ADV-2007-3087",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/3386",
          "name" : "ADV-2007-3386",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0065",
          "name" : "ADV-2008-0065",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1979/references",
          "name" : "ADV-2008-1979",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/0233",
          "name" : "ADV-2009-0233",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32988",
          "name" : "tomcat-proxy-directory-traversal(32988)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190413 svn commit: r1857494 [18/20] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190319 svn commit: r1855831 [21/30] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190415 svn commit: r1857582 [20/22] - in /tomcat/site/trunk: docs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190325 svn commit: r1856174 [25/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190319 svn commit: r1855831 [26/30] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190325 svn commit: r1856174 [19/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r5c616dfc49156e4b06ffab842800c80f4425924d0f20c452c127a53c@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200213 svn commit: r1873980 [30/34] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200213 svn commit: r1873980 [24/34] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200203 svn commit: r1873527 [26/30] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10643",
          "name" : "oval:org.mitre.oval:def:10643",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) \"/\" (slash), (2) \"\\\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.0.0",
          "versionEndExcluding" : "5.5.22"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "6.0.0",
          "versionEndExcluding" : "6.0.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-16T22:19Z",
    "lastModifiedDate" : "2019-04-15T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0451",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "spamassassin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://fedoranews.org/cms/node/2657",
          "name" : "FEDORA-2007-242",
          "refsource" : "FEDORA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2659",
          "name" : "FEDORA-2007-241",
          "refsource" : "FEDORA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://osvdb.org/33207",
          "name" : "33207",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0074.html",
          "name" : "RHSA-2007:0074",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24197",
          "name" : "24197",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24200",
          "name" : "24200",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24250",
          "name" : "24250",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24256",
          "name" : "24256",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24265",
          "name" : "24265",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24307",
          "name" : "24307",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24889",
          "name" : "24889",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-02.xml",
          "name" : "GLSA-200703-02",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://spamassassin.apache.org/advisories/cve-2007-0451.txt",
          "name" : "http://spamassassin.apache.org/advisories/cve-2007-0451.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt",
          "name" : "http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:049",
          "name" : "MDKSA-2007:049",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_6_sr.html",
          "name" : "SUSE-SR:2007:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0075.html",
          "name" : "RHSA-2007:0075",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22584",
          "name" : "22584",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017666",
          "name" : "1017666",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0628",
          "name" : "ADV-2007-0628",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32536",
          "name" : "spamassassin-url-dos(32536)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1073",
          "name" : "https://issues.rpath.com/browse/RPL-1073",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10018",
          "name" : "oval:org.mitre.oval:def:10018",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers \"massive memory usage.\""
        }, {
          "lang" : "en",
          "value" : "Upgrade to SpamAssassin version 3.1.8"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:spamassassin:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:spamassassin:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:spamassassin:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:spamassassin:3.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:spamassassin:3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:spamassassin:3.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:spamassassin:3.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:spamassassin:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.1.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-16T19:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0452",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "samba",
            "product" : {
              "product_data" : [ {
                "product_name" : "samba",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.14a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.20a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.20b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.21a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.21b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.21c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.23a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.23b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.23c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.23d",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc",
          "name" : "20070201-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2579",
          "name" : "FEDORA-2007-219",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2580",
          "name" : "FEDORA-2007-220",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00943462",
          "name" : "SSRT071341",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Feb/0002.html",
          "name" : "SUSE-SA:2007:016",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33100",
          "name" : "33100",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24021",
          "name" : "24021",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24030",
          "name" : "24030",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24046",
          "name" : "24046",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24060",
          "name" : "24060",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24067",
          "name" : "24067",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24076",
          "name" : "24076",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24101",
          "name" : "24101",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24140",
          "name" : "24140",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24145",
          "name" : "24145",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24151",
          "name" : "24151",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24188",
          "name" : "24188",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24284",
          "name" : "24284",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24792",
          "name" : "24792",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2219",
          "name" : "2219",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017587",
          "name" : "1017587",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.476916",
          "name" : "SSA:2007-038-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1",
          "name" : "200588",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://us1.samba.org/samba/security/CVE-2007-0452.html",
          "name" : "http://us1.samba.org/samba/security/CVE-2007-0452.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1257",
          "name" : "DSA-1257",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200702-01.xml",
          "name" : "GLSA-200702-01",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:034",
          "name" : "MDKSA-2007:034",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0060.html",
          "name" : "RHSA-2007:0060",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0061.html",
          "name" : "RHSA-2007:0061",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459167/100/0/threaded",
          "name" : "20070205 [SAMBA-SECURITY] CVE-2007-0452: Potential DoS against smbd in Samba 3.0.6 - 3.0.23d",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459365/100/0/threaded",
          "name" : "20070207 rPSA-2007-0026-1 samba samba-swat",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22395",
          "name" : "22395",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0007",
          "name" : "2007-0007",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-419-1",
          "name" : "USN-419-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0483",
          "name" : "ADV-2007-0483",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1278",
          "name" : "ADV-2007-1278",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32301",
          "name" : "samba-smbd-filerename-dos(32301)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1005",
          "name" : "https://issues.rpath.com/browse/RPL-1005",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9758",
          "name" : "oval:org.mitre.oval:def:9758",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.14a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.20a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.20b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.21a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.21b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.21c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.23a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.23b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.23c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.23d:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0453",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "samba",
            "product" : {
              "product_data" : [ {
                "product_name" : "samba",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.21a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.21b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.21c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.23a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.23b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.23c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.23d",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33098",
          "name" : "33098",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24043",
          "name" : "24043",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24101",
          "name" : "24101",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24151",
          "name" : "24151",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017589",
          "name" : "1017589",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.476916",
          "name" : "SSA:2007-038-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://us1.samba.org/samba/security/CVE-2007-0453.html",
          "name" : "http://us1.samba.org/samba/security/CVE-2007-0453.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html",
          "name" : "OpenPKG-SA-2007.012",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459168/100/0/threaded",
          "name" : "20070205 [SAMBA-SECURITY] CVE-2007-0453: Buffer overrun in nss_winbind.so.1 on Solaris",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459365/100/0/threaded",
          "name" : "20070207 rPSA-2007-0026-1 samba samba-swat",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22410",
          "name" : "22410",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0007",
          "name" : "2007-0007",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0483",
          "name" : "ADV-2007-0483",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32231",
          "name" : "samba-winbind-bo(32231)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1005",
          "name" : "https://issues.rpath.com/browse/RPL-1005",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the nss_winbind.so.1 library in Samba 3.0.21 through 3.0.23d, as used in the winbindd daemon on Solaris, allows attackers to execute arbitrary code via the (1) gethostbyname and (2) getipnodebyname functions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.21a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.21b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.21c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.23a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.23b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.23c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.23d:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0454",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "samba",
            "product" : {
              "product_data" : [ {
                "product_name" : "samba",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.14a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.20a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.20b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.21a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.21b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.21c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.23d",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mandrakesoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "mandrake_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mandrake_linux_corporate_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mandrake_linuxsoft_2007",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33101",
          "name" : "33101",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24021",
          "name" : "24021",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24046",
          "name" : "24046",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24060",
          "name" : "24060",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24067",
          "name" : "24067",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24101",
          "name" : "24101",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24145",
          "name" : "24145",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24151",
          "name" : "24151",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017588",
          "name" : "1017588",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.476916",
          "name" : "SSA:2007-038-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://us1.samba.org/samba/security/CVE-2007-0454.html",
          "name" : "http://us1.samba.org/samba/security/CVE-2007-0454.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1257",
          "name" : "DSA-1257",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200702-01.xml",
          "name" : "GLSA-200702-01",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/649732",
          "name" : "VU#649732",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:034",
          "name" : "MDKSA-2007:034",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html",
          "name" : "OpenPKG-SA-2007.012",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459179/100/0/threaded",
          "name" : "20070205 [SAMBA-SECURITY] CVE-2007-0454: Format string bug in afsacl.so VFS plugin",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459365/100/0/threaded",
          "name" : "20070207 rPSA-2007-0026-1 samba samba-swat",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22403",
          "name" : "22403",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0007",
          "name" : "2007-0007",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-419-1",
          "name" : "USN-419-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0483",
          "name" : "ADV-2007-0483",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32304",
          "name" : "samba-afsacl-format-string(32304)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1005",
          "name" : "https://issues.rpath.com/browse/RPL-1005",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.14a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.20a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.20b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.21a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.21b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.21c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:3.0.23d:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:arm:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:hppa:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:ia-32:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:ia-64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:m68k:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:mips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:mipsel:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:ppc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:s-390:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:amd64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:arm:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:hppa:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ia-32:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ia-64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:m68k:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:mips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:mipsel:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ppc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:s-390:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2006:*:x86_64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:x86_64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:x86_64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linuxsoft_2007:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linuxsoft_2007:*:*:x86_64:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0455",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gd_graphics_library",
            "product" : {
              "product_data" : [ {
                "product_name" : "gdlib",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.33",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=224607",
          "name" : "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=224607",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2631",
          "name" : "FEDORA-2007-150",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html",
          "name" : "FEDORA-2010-19033",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html",
          "name" : "FEDORA-2010-19022",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.rpath.com/pipermail/security-announce/2007-February/000145.html",
          "name" : "[security-announce] 20070208 rPSA-2007-0028-1 gd",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0155.html",
          "name" : "RHSA-2007:0155",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23916",
          "name" : "23916",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24022",
          "name" : "24022",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24052",
          "name" : "24052",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24053",
          "name" : "24053",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24107",
          "name" : "24107",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24143",
          "name" : "24143",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24151",
          "name" : "24151",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24924",
          "name" : "24924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24945",
          "name" : "24945",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24965",
          "name" : "24965",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25575",
          "name" : "25575",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/29157",
          "name" : "29157",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/42813",
          "name" : "42813",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:035",
          "name" : "MDKSA-2007:035",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:036",
          "name" : "MDKSA-2007:036",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:038",
          "name" : "MDKSA-2007:038",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:109",
          "name" : "MDKSA-2007:109",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0153.html",
          "name" : "RHSA-2007:0153",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0162.html",
          "name" : "RHSA-2007:0162",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0146.html",
          "name" : "RHSA-2008:0146",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/466166/100/0/threaded",
          "name" : "20070418 rPSA-2007-0073-1 php php-mysql php-pgsql",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22289",
          "name" : "22289",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0007",
          "name" : "2007-0007",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-473-1",
          "name" : "USN-473-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0400",
          "name" : "ADV-2007-0400",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2011/0022",
          "name" : "ADV-2011-0022",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1030",
          "name" : "https://issues.rpath.com/browse/RPL-1030",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1268",
          "name" : "https://issues.rpath.com/browse/RPL-1268",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11303",
          "name" : "oval:org.mitre.oval:def:11303",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gd_graphics_library:gdlib:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gd_graphics_library:gdlib:2.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gd_graphics_library:gdlib:2.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gd_graphics_library:gdlib:2.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gd_graphics_library:gdlib:2.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gd_graphics_library:gdlib:2.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gd_graphics_library:gdlib:2.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gd_graphics_library:gdlib:2.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gd_graphics_library:gdlib:2.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gd_graphics_library:gdlib:2.0.33:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0456",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wireshark",
            "product" : {
              "product_data" : [ {
                "product_name" : "wireshark",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.99.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc",
          "name" : "20070301-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2565",
          "name" : "FEDORA-2007-207",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33073",
          "name" : "33073",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24011",
          "name" : "24011",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24016",
          "name" : "24016",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24025",
          "name" : "24025",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24084",
          "name" : "24084",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24515",
          "name" : "24515",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24650",
          "name" : "24650",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24970",
          "name" : "24970",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017581",
          "name" : "1017581",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:033",
          "name" : "MDKSA-2007:033",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0066.html",
          "name" : "RHSA-2007:0066",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22352",
          "name" : "22352",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0443",
          "name" : "ADV-2007-0443",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.wireshark.org/security/wnpa-sec-2007-01.html",
          "name" : "http://www.wireshark.org/security/wnpa-sec-2007-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32056",
          "name" : "wireshark-lltdissector-dos(32056)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-985",
          "name" : "https://issues.rpath.com/browse/RPL-985",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11342",
          "name" : "oval:org.mitre.oval:def:11342",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14867",
          "name" : "oval:org.mitre.oval:def:14867",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.99.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.99.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-02T20:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0457",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wireshark",
            "product" : {
              "product_data" : [ {
                "product_name" : "wireshark",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc",
          "name" : "20070301-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2565",
          "name" : "FEDORA-2007-207",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33074",
          "name" : "33074",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24011",
          "name" : "24011",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24016",
          "name" : "24016",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24025",
          "name" : "24025",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24084",
          "name" : "24084",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24515",
          "name" : "24515",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24650",
          "name" : "24650",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24970",
          "name" : "24970",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017581",
          "name" : "1017581",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:033",
          "name" : "MDKSA-2007:033",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0066.html",
          "name" : "RHSA-2007:0066",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22352",
          "name" : "22352",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0443",
          "name" : "ADV-2007-0443",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.wireshark.org/security/wnpa-sec-2007-01.html",
          "name" : "http://www.wireshark.org/security/wnpa-sec-2007-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32055",
          "name" : "wireshark-ieeedissector-dos(32055)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-985",
          "name" : "https://issues.rpath.com/browse/RPL-985",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11003",
          "name" : "oval:org.mitre.oval:def:11003",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.10.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.10.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.10.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.10.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.10.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.99.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.99.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.99.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.99.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-02T20:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0458",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wireshark",
            "product" : {
              "product_data" : [ {
                "product_name" : "wireshark",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.99.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc",
          "name" : "20070301-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2565",
          "name" : "FEDORA-2007-207",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33075",
          "name" : "33075",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24011",
          "name" : "24011",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24016",
          "name" : "24016",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24025",
          "name" : "24025",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24084",
          "name" : "24084",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24515",
          "name" : "24515",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24650",
          "name" : "24650",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24970",
          "name" : "24970",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017581",
          "name" : "1017581",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:033",
          "name" : "MDKSA-2007:033",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0066.html",
          "name" : "RHSA-2007:0066",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22352",
          "name" : "22352",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0443",
          "name" : "ADV-2007-0443",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.wireshark.org/security/wnpa-sec-2007-01.html",
          "name" : "http://www.wireshark.org/security/wnpa-sec-2007-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32054",
          "name" : "wireshark-httpdissector-dos(32054)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-985",
          "name" : "https://issues.rpath.com/browse/RPL-985",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10966",
          "name" : "oval:org.mitre.oval:def:10966",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14836",
          "name" : "oval:org.mitre.oval:def:14836",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors, a different issue than CVE-2006-5468."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.99.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.99.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-02T20:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0459",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wireshark",
            "product" : {
              "product_data" : [ {
                "product_name" : "wireshark",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.99.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc",
          "name" : "20070301-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1200",
          "name" : "http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1200",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2565",
          "name" : "FEDORA-2007-207",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24011",
          "name" : "24011",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24016",
          "name" : "24016",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24025",
          "name" : "24025",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24084",
          "name" : "24084",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24515",
          "name" : "24515",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24650",
          "name" : "24650",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24970",
          "name" : "24970",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017581",
          "name" : "1017581",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:033",
          "name" : "MDKSA-2007:033",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0066.html",
          "name" : "RHSA-2007:0066",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22352",
          "name" : "22352",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0443",
          "name" : "ADV-2007-0443",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.wireshark.org/security/wnpa-sec-2007-01.html",
          "name" : "http://www.wireshark.org/security/wnpa-sec-2007-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32053",
          "name" : "wireshark-tcpdissector-dos(32053)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-985",
          "name" : "https://issues.rpath.com/browse/RPL-985",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10465",
          "name" : "oval:org.mitre.oval:def:10465",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14875",
          "name" : "oval:org.mitre.oval:def:14875",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.99.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.99.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wireshark:wireshark:0.99.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-02T20:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0460",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "suse",
            "product" : {
              "product_data" : [ {
                "product_name" : "suse_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32939",
          "name" : "32939",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23863",
          "name" : "23863",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24524",
          "name" : "24524",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-17.xml",
          "name" : "GLSA-200703-17",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:028",
          "name" : "MDKSA-2007:028",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_01_sr.html",
          "name" : "SUSE-SR:2007:001",
          "refsource" : "SUSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22139",
          "name" : "22139",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to \"improper string length calculations.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "10.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-24T01:28Z",
    "lastModifiedDate" : "2010-09-15T05:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0461",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dazuko",
            "product" : {
              "product_data" : [ {
                "product_name" : "dazuko",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/38322",
          "name" : "38322",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_01_sr.html",
          "name" : "SUSE-SR:2007:001",
          "refsource" : "SUSE",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple memory leaks in the Dazuko anti-virus helper module before 2.3.2 allow attackers to cause a denial of service (memory consumption) via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dazuko:dazuko:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-24T01:28Z",
    "lastModifiedDate" : "2008-11-13T06:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0462",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://projects.info-pull.com/moab/MOAB-23-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-23-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23859",
          "name" : "23859",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32696",
          "name" : "32696",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22207",
          "name" : "22207",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0337",
          "name" : "ADV-2007-0337",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31698",
          "name" : "macos-argb-dos(31698)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0463",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "software_update",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-24-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-24-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32703",
          "name" : "32703",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22222",
          "name" : "22222",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017755",
          "name" : "1017755",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0337",
          "name" : "ADV-2007-0337",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:software_update:2.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T16:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0464",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cfnetwork",
            "product" : {
              "product_data" : [ {
                "product_name" : "cfnetwork",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "129.19",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307041",
          "name" : "http://docs.info.apple.com/article.html?artnum=307041",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html",
          "name" : "APPLE-SA-2007-11-14",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-25-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-25-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/27643",
          "name" : "27643",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/32704",
          "name" : "32704",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22249",
          "name" : "22249",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/26444",
          "name" : "26444",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-319A.html",
          "name" : "TA07-319A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/3868",
          "name" : "ADV-2007-3868",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31837",
          "name" : "macos-cfnetwork-dos(31837)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3200",
          "name" : "3200",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application crash) via a crafted HTTP 301 response, which results in a NULL pointer dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.10:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cfnetwork:cfnetwork:129.19:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0465",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "installer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-26-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-26-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32705",
          "name" : "32705",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22272",
          "name" : "22272",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017940",
          "name" : "1017940",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31883",
          "name" : "macos-installer-format-string(31883)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:installer:2.1.5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-31T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0466",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "telestream",
            "product" : {
              "product_data" : [ {
                "product_name" : "flip4mac_windows_media_components_for_quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.0.33",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://projects.info-pull.com/moab/MOAB-27-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-27-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/23958",
          "name" : "23958",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/32697",
          "name" : "32697",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22286",
          "name" : "22286",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0389",
          "name" : "ADV-2007-0389",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Properties_Object size field in a WMV file, which triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:telestream:flip4mac_windows_media_components_for_quicktime:2.1.0.33:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T01:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0467",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-28-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-28-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/363112",
          "name" : "VU#363112",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/32706",
          "name" : "32706",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017751",
          "name" : "1017751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31888",
          "name" : "macos-crashreporterd-privilege-escalation(31888)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that the attacker is already a part of the administrator group."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.2
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 1.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0468",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "visual_studio",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31607",
          "name" : "31607",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23856",
          "name" : "23856",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2172",
          "name" : "2172",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.anspi.pl/~porkythepig/visualization/rc-kupiekrowe.cpp",
          "name" : "http://www.anspi.pl/~porkythepig/visualization/rc-kupiekrowe.cpp",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457646/100/0/threaded",
          "name" : "20070122 Microsoft Visual C++ (.RC) resource files buffer overflow vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0296",
          "name" : "ADV-2007-0296",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31665",
          "name" : "visualstudio-rc-bo(31665)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in rcdll.dll in msdev.exe in Visual C++ (MSVC) in Microsoft Visual Studio 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a long file path in the \"1 TYPELIB MOVEABLE PURE\" option in an RC file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visual_studio:6.0:sp6:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-24T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0469",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rubyforge",
            "product" : {
              "product_data" : [ {
                "product_name" : "rubygems",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=116939816621060&w=2",
          "name" : "20070121 RubyGems 0.9.0 and earlier installation exploit",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://rubyforge.org/frs/shownotes.php?release_id=9074",
          "name" : "http://rubyforge.org/frs/shownotes.php?release_id=9074",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_4_sr.html",
          "name" : "SUSE-SR:2007:004",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458128/100/0/threaded",
          "name" : "20070121 RubyGems 0.9.0 and earlier installation exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0295",
          "name" : "ADV-2007-0295",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31688",
          "name" : "rubygems-extractfiles-file-overwrite(31688)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyforge:rubygems:0.8.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyforge:rubygems:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-24T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0470",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sunos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31616",
          "name" : "31616",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23821",
          "name" : "23821",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017546",
          "name" : "1017546",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102773-1",
          "name" : "102773",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22190",
          "name" : "22190",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0317",
          "name" : "ADV-2007-0317",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31669",
          "name" : "solaris-tip-privilege-escalation(31669)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2038",
          "name" : "oval:org.mitre.oval:def:2038",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uucp account privileges via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-24T01:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0471",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "checkpoint",
            "product" : {
              "product_data" : [ {
                "product_name" : "connectra_ngx",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r62",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051920.html",
          "name" : "20070122 Check Point Connectra End Point security bypass",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/31655",
          "name" : "31655",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23847",
          "name" : "23847",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secureknowledge.checkpoint.com/SecureKnowledge/viewSolutionDocument.do?lid=sk32472",
          "name" : "http://secureknowledge.checkpoint.com/SecureKnowledge/viewSolutionDocument.do?lid=sk32472",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2179",
          "name" : "2179",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017559",
          "name" : "1017559",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017560",
          "name" : "1017560",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://updates.checkpoint.com/fileserver/ID/7126/FILE/VPN-1_Hotfix1.pdf",
          "name" : "http://updates.checkpoint.com/fileserver/ID/7126/FILE/VPN-1_Hotfix1.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.checkpoint.com/downloads/latest/hfa/connectra/security_r62.html",
          "name" : "http://www.checkpoint.com/downloads/latest/hfa/connectra/security_r62.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.checkpoint.com/downloads/latest/hfa/vpn1_security/vpn1_R62_Windows.html",
          "name" : "http://www.checkpoint.com/downloads/latest/hfa/vpn1_security/vpn1_R62_Windows.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457621/100/0/threaded",
          "name" : "20070122 Re: [Full-disclosure] Check Point Connectra End Point security bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457683/100/0/threaded",
          "name" : "20070122 Check Point Connectra End Point security bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0276",
          "name" : "ADV-2007-0276",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31646",
          "name" : "checkpoint-params-security-bypass(31646)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:checkpoint:connectra_ngx:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "r62"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-24T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0472",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "smb4k",
            "product" : {
              "product_data" : [ {
                "product_name" : "smb4k",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769",
          "name" : "http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=11706",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=11706",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=11902",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=11902",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=9777",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=9777",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html",
          "name" : "SUSE-SR:2007:002",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23937",
          "name" : "23937",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23984",
          "name" : "23984",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24111",
          "name" : "24111",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24469",
          "name" : "24469",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml",
          "name" : "GLSA-200703-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:042",
          "name" : "MDKSA-2007:042",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22299",
          "name" : "22299",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0393",
          "name" : "ADV-2007-0393",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html",
          "name" : "[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple race conditions in Smb4K before 0.8.0 allow local users to (1) modify arbitrary files via unspecified manipulations of Smb4K's lock file, which is not properly handled by the remove_lock_file function in core/smb4kfileio.cpp, and (2) add lines to the sudoers file via a symlink attack on temporary files, which isn't properly handled by the writeFile function in core/smb4kfileio.cpp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T23:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0473",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "smb4k",
            "product" : {
              "product_data" : [ {
                "product_name" : "smb4k",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769",
          "name" : "http://developer.berlios.de/bugs/?func=detailbug&bug_id=9630&group_id=769",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=11706",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=11706",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=11902",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=11902",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=9777",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=9777",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html",
          "name" : "SUSE-SR:2007:002",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23937",
          "name" : "23937",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23984",
          "name" : "23984",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24111",
          "name" : "24111",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24469",
          "name" : "24469",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml",
          "name" : "GLSA-200703-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:042",
          "name" : "MDKSA-2007:042",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22299",
          "name" : "22299",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0393",
          "name" : "ADV-2007-0393",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html",
          "name" : "[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T23:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0474",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "smb4k",
            "product" : {
              "product_data" : [ {
                "product_name" : "smb4k",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://developer.berlios.de/bugs/?func=detailbug&bug_id=9631&group_id=769",
          "name" : "http://developer.berlios.de/bugs/?func=detailbug&bug_id=9631&group_id=769",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=11706",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=11706",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=11902",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=11902",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=9777",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=9777",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html",
          "name" : "SUSE-SR:2007:002",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23937",
          "name" : "23937",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23984",
          "name" : "23984",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24111",
          "name" : "24111",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24469",
          "name" : "24469",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml",
          "name" : "GLSA-200703-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:042",
          "name" : "MDKSA-2007:042",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22299",
          "name" : "22299",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0393",
          "name" : "ADV-2007-0393",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html",
          "name" : "[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to kill arbitrary processes, related to a \"design issue with smb4k_kill.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.3
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T23:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0475",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "smb4k",
            "product" : {
              "product_data" : [ {
                "product_name" : "smb4k",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://developer.berlios.de/bugs/?func=detailbug&bug_id=9631&group_id=769",
          "name" : "http://developer.berlios.de/bugs/?func=detailbug&bug_id=9631&group_id=769",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=11706",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=11706",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=11902",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=11902",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=9777",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=9777",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html",
          "name" : "SUSE-SR:2007:002",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23937",
          "name" : "23937",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23984",
          "name" : "23984",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24111",
          "name" : "24111",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24469",
          "name" : "24469",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml",
          "name" : "GLSA-200703-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:042",
          "name" : "MDKSA-2007:042",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22299",
          "name" : "22299",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0393",
          "name" : "ADV-2007-0393",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html",
          "name" : "[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in utilities/smb4k_*.cpp in Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to gain privileges via unspecified vectors related to the args variable and unspecified other variables, in conjunction with the sudo configuration."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smb4k:smb4k:0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T23:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0476",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gentoo",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.30",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31617",
          "name" : "31617",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23881",
          "name" : "23881",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200701-19.xml",
          "name" : "GLSA-200701-19",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22195",
          "name" : "22195",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0305",
          "name" : "ADV-2007-0305",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:gentoo:linux:2.1.30:r9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:gentoo:linux:2.2.28:r7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:gentoo:linux:2.3.30:r2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0477",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openads",
            "product" : {
              "product_data" : [ {
                "product_name" : "openads",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.30",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forum.openads.org/index.php?showtopic=503412651",
          "name" : "http://forum.openads.org/index.php?showtopic=503412651",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://jvn.jp/jp/JVN%2307274813/index.html",
          "name" : "JVN#07274813",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32926",
          "name" : "32926",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457990/100/200/threaded",
          "name" : "20070124 [OPENADS-SA-2007-001] phpAdsNew and phpPgAds 2.0.9-pr1 vulnerability fixed",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458197/100/100/threaded",
          "name" : "20070126 [OPENADS-SA-2007-002] Max Media Manager v0.1.29 and v0.3.30 vulnerability fixed",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458296/100/100/threaded",
          "name" : "20070127 Re: [OPENADS-SA-2007-002] Max Media Manager v0.1.29 and v0.3.30 vulnerability fixed",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0315",
          "name" : "ADV-2007-0315",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://developer.openads.org/browser/branches/max/trunk/CHANGELOG.txt?format=raw",
          "name" : "https://developer.openads.org/browser/branches/max/trunk/CHANGELOG.txt?format=raw",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Openads 2.0.x before 2.0.10, 2.3 before 2.3.31 (aka Max Media Manager before 0.3.31-alpha-pr2), and phpAdsNew/phpPgAds before 2.0.9-pr1 allows remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in admin-search.php and (2) affiliate-search.php. NOTE: this issue may overlap CVE-2007-0363."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openads:openads:2.3.30:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0478",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "webcore",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=306172",
          "name" : "http://docs.info.apple.com/article.html?artnum=306172",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html",
          "name" : "APPLE-SA-2007-07-31",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32712",
          "name" : "32712",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23893",
          "name" : "23893",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26235",
          "name" : "26235",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1018494",
          "name" : "1018494",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.beanfuzz.com/wordpress/?p=99",
          "name" : "http://www.beanfuzz.com/wordpress/?p=99",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457763/100/0/threaded",
          "name" : "20070123 Safari Improperly Parses HTML Documents & BlogSpot XSS vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25159",
          "name" : "25159",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2732",
          "name" : "ADV-2007-2732",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31846",
          "name" : "safari-html-comment-xss(31846)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.10:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:webcore:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0479",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "ios_transmission_control_protocol",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0da",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0db",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0dc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0st",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0w",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0wc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0wt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xm",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1aa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ax",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ay",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1az",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1cx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1da",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1db",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1dc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ea",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1eb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ec",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1eo",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1eu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ev",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ew",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ex",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ey",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ez",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ye",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2bc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2bw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2by",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2bz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2cx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2cy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2cz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2da",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2dd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2dx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2eu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ew",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ewa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ex",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ey",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ez",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2fx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2fy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2fz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ixa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ixb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ixc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ja",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2jk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2mb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2mc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sbc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2se",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sea",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2seb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sec",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sed",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2see",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sef",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2seg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sga",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2so",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sra",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2srb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2su",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2tpc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xm",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ye",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ym",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yo",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ys",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2za",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ze",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3bc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3bw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ja",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3jea",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3jeb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3jk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3jx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3tpc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ym",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ys",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4mr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4sw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xc",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32093",
          "name" : "32093",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23867",
          "name" : "23867",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017551",
          "name" : "1017551",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb0e4.shtml",
          "name" : "20070124 Crafted TCP Packet Can Cause Denial of Service",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/217912",
          "name" : "VU#217912",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22208",
          "name" : "22208",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-024A.html",
          "name" : "TA07-024A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0329",
          "name" : "ADV-2007-0329",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31716",
          "name" : "cisco-tcp-ipv4-dos(31716)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5080",
          "name" : "oval:org.mitre.oval:def:5080",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0da:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0db:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0dc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0st:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0w:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0wc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0wt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xm:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1aa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ax:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ay:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1az:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1cx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1da:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1db:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1dc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ea:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1eb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ec:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1eo:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1eu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ev:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ew:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ex:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ey:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ez:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1x:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ye:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2bc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2bw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2by:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2bz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2cx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2cy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2cz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2da:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2dd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2dx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2eu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ew:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ewa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ex:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ey:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ez:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2fx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2fy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2fz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ixa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ixb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ixc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ja:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2jk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2mb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2mc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sbc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2se:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sea:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2seb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sec:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sed:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2see:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sef:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2seg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sga:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2so:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sra:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2srb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2su:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2tpc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xm:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ye:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ym:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yo:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ys:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2za:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ze:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3bc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3bw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3ja:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3jea:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3jeb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3jk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3jx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3tpc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3ym:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3ys:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4mr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4sw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4xc:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0480",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "ios_transmission_control_protocol",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0da",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0db",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0dc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0st",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0w",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0wc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0wt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xm",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1aa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ax",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ay",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1az",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1cx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1da",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1db",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1dc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ea",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1eb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ec",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1eo",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1eu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ev",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ew",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ex",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ey",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ez",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ye",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2bc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2bw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2by",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2bz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2cx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2cy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2cz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2da",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2dd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2dx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2eu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ew",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ewa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ex",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ey",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ez",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2fx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2fy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2fz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ixa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ixb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ixc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ja",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2jk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2mb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2mc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sbc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2se",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sea",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2seb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sec",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sed",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2see",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sef",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2seg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sga",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2so",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sra",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2srb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2su",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2tpc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xm",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ye",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ym",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yo",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ys",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2za",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ze",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3bc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3bw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ja",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3jea",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3jeb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3jk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3jx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3tpc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ym",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ys",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4mr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4sw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xc",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32092",
          "name" : "32092",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23867",
          "name" : "23867",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017555",
          "name" : "1017555",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb157.shtml",
          "name" : "20070124 Crafted IP Option Vulnerability",
          "refsource" : "CISCO",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/341288",
          "name" : "VU#341288",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22211",
          "name" : "22211",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-024A.html",
          "name" : "TA07-024A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0329",
          "name" : "ADV-2007-0329",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31725",
          "name" : "cisco-ip-option-code-execution(31725)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5666",
          "name" : "oval:org.mitre.oval:def:5666",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in the IP header in a (1) ICMP, (2) PIMv2, (3) PGM, or (4) URD packet."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0da:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0db:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0dc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0st:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0w:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0wc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0wt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xm:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1aa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ax:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ay:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1az:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1cx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1da:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1db:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1dc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ea:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1eb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ec:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1eo:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1eu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ev:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ew:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ex:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ey:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ez:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1x:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ye:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2bc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2bw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2by:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2bz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2cx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2cy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2cz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2da:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2dd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2dx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2eu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ew:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ewa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ex:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ey:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ez:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2fx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2fy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2fz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ixa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ixb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ixc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ja:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2jk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2mb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2mc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sbc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2se:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sea:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2seb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sec:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sed:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2see:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sef:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2seg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sga:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2so:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sra:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2srb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2su:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2tpc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xm:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ye:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ym:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yo:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ys:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2za:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ze:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3bc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3bw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3ja:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3jea:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3jeb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3jk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3jx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3tpc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3ym:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3ys:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4mr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4sw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4xc:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0481",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "ios_transmission_control_protocol",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0da",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0db",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0dc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0st",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0w",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0wc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0wt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xm",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1aa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ax",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ay",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1az",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1cx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1da",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1db",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1dc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ea",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1eb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ec",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1eo",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1eu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ev",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ew",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ex",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ey",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ez",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ye",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2bc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2bw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2by",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2bz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2cx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2cy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2cz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2da",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2dd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2dx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2eu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ew",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ewa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ex",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ey",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ez",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2fx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2fy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2fz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ixa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ixb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ixc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ja",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2jk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2mb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2mc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sbc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2se",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sea",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2seb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sec",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sed",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2see",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sef",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2seg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sga",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2so",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sra",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2srb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2su",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2tpc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xm",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ye",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ym",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yo",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ys",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2za",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ze",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3bc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3bw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ja",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3jea",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3jeb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3jk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3jx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3tpc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ym",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ys",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4mr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4sw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xc",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32091",
          "name" : "32091",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23867",
          "name" : "23867",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017550",
          "name" : "1017550",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb0fd.shtml",
          "name" : "20070124 IPv6 Routing Header Vulnerability",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/274760",
          "name" : "VU#274760",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22210",
          "name" : "22210",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-024A.html",
          "name" : "TA07-024A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0329",
          "name" : "ADV-2007-0329",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31715",
          "name" : "cisco-ios-ipv6-type0-dos(31715)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5857",
          "name" : "oval:org.mitre.oval:def:5857",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0da:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0db:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0dc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0st:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0sz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0w:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0wc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0wt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xm:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.0xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1aa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ax:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ay:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1az:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1cx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1da:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1db:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1dc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ea:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1eb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ec:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1eo:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1eu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ev:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ew:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ex:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ey:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ez:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1x:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1xz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1ye:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.1yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2bc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2bw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2by:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2bz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2cx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2cy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2cz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2da:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2dd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2dx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2eu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ew:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ewa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ex:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ey:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ez:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2fx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2fy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2fz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ixa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ixb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ixc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ja:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2jk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2mb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2mc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sbc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2se:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sea:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2seb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sec:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sed:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2see:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sef:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2seg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sga:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2so:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sra:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2srb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2su:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sxf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2sz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2tpc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xm:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ye:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ym:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yo:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ys:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2yz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2za:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2ze:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.2zp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3bc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3bw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3ja:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3jea:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3jeb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3jk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3jx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3tpc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3xy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3ym:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3ys:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.3yz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4mr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4sw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios_transmission_control_protocol:12.4xc:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0482",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "ray_server_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31671",
          "name" : "31671",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23900",
          "name" : "23900",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017547",
          "name" : "1017547",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102779-1",
          "name" : "102779",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22192",
          "name" : "22192",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0316",
          "name" : "ADV-2007-0316",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31700",
          "name" : "sunray-utadmin-information-disclosure(31700)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "cgi-bin/main in Sun Ray Server Software 2.0 and 3.0 before 20070123 allows local users to obtain the utadmin password by reading a web server's log file, or by conducting a different, unspecified local attack."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:ray_server_software:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:ray_server_software:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0483",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "enthusiast",
            "product" : {
              "product_data" : [ {
                "product_name" : "enthusiast",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31608",
          "name" : "31608",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23865",
          "name" : "23865",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22180",
          "name" : "22180",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31667",
          "name" : "enthusiast-show-xss(31667)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Enthusiast 3.1 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) show_owned.php or (2) show_joined.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:enthusiast:enthusiast:3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0484",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "enthusiast",
            "product" : {
              "product_data" : [ {
                "product_name" : "enthusiast",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31609",
          "name" : "31609",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31610",
          "name" : "31610",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23865",
          "name" : "23865",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22180",
          "name" : "22180",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31666",
          "name" : "enthusiast-show-sql-injection(31666)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Enthusiast 3.1 allow remote attackers to execute arbitrary SQL commands via the cat parameter to (1) show_owned.php, (2) show_joined.php, and possibly other files. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:enthusiast:enthusiast:3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0485",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webchat.org",
            "product" : {
              "product_data" : [ {
                "product_name" : "webchat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.77",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/8206",
          "name" : "8206",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/313610/30/25700/threaded",
          "name" : "20030303 WebChat (PHP)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/7000",
          "name" : "7000",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1006193",
          "name" : "1006193",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31624",
          "name" : "webchat-definesphp-file-include(31624)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3169",
          "name" : "3169",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATPATH parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webchat.org:webchat:0.77:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0486",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpadsnew",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpadsnew",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33573",
          "name" : "33573",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2174",
          "name" : "2174",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457670/100/0/threaded",
          "name" : "20070120 phpAdsNew 2.0.7 Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457806/100/200/threaded",
          "name" : "20070122 Re: phpAdsNew 2.0.7 Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457991/100/200/threaded",
          "name" : "20070124 Re: phpAdsNew 2.0.7 Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22172",
          "name" : "22172",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in Openads (aka phpAdsNew) 2.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) phpAds_geoPlugin parameter to libraries/lib-remotehost.inc, the (2) filename parameter to admin/report-index, or the (3) phpAds_config[my_footer] parameter to admin/lib-gui.inc.  NOTE: the vendor has disputed this issue, stating that the relevant variables are used within function definitions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpadsnew:phpadsnew:2.0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0487",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zoneo-soft",
            "product" : {
              "product_data" : [ {
                "product_name" : "freeforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/457643/100/0/threaded",
          "name" : "20070121 FreeForum 0.9.0 <=- (index.php fpath) Remote File Include Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457958/100/0/threaded",
          "name" : "20070124 Re: FreeForum 0.9.0 <=- (index.php fpath) Remote File Include Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31647",
          "name" : "freeforum-index-file-include(31647)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue has been disputed by third party researchers, stating that fpath variable is initialized before being used."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:0.9.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0488",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "huawei",
            "product" : {
              "product_data" : [ {
                "product_name" : "versatile_routing_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.43_2500e-003_firmware",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051856.html",
          "name" : "20070118 The Quidway Router local DOS",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/40355",
          "name" : "40355",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2176",
          "name" : "2176",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31641",
          "name" : "quidway-arp-dos(31641)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Huawei Versatile Routing Platform 1.43 2500E-003 firmware on the Quidway R1600 Router, and possibly other models, allows remote attackers to cause a denial of service (device crash) via a long show arp command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:huawei:versatile_routing_platform:1.43_2500e-003_firmware:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0489",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "visohotlink",
            "product" : {
              "product_data" : [ {
                "product_name" : "visohotlink",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31611",
          "name" : "31611",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23878",
          "name" : "23878",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22171",
          "name" : "22171",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0285",
          "name" : "ADV-2007-0285",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31654",
          "name" : "visohotlink-functions-file-include(31654)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3175",
          "name" : "3175",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:visohotlink:visohotlink:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.01"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0490",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "open-realty",
            "product" : {
              "product_data" : [ {
                "product_name" : "open-realty",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/457676/100/0/threaded",
          "name" : "20070121 Full Path Disclosure in Open-Realty ( v2.3.4 )",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31657",
          "name" : "openrealty-index-path-disclosure(31657)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open-realty:open-realty:2.3.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0491",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sky_gunning",
            "product" : {
              "product_data" : [ {
                "product_name" : "myspeach",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23850",
          "name" : "23850",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0269",
          "name" : "ADV-2007-0269",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter, a different vector than CVE-2006-4630.  NOTE: Some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sky_gunning:myspeach:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0492",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webspell",
            "product" : {
              "product_data" : [ {
                "product_name" : "webspell",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.01.02",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.vupen.com/english/advisories/2007/0270",
          "name" : "ADV-2007-0270",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31632",
          "name" : "webspell-gallery-sql-injection(31632)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) galleryID parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webspell:webspell:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.01.02"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0493",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "isc",
            "product" : {
              "product_data" : [ {
                "product_name" : "bind",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305530",
          "name" : "http://docs.info.apple.com/article.html?artnum=305530",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2507",
          "name" : "FEDORA-2007-147",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2537",
          "name" : "FEDORA-2007-164",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc",
          "name" : "NetBSD-SA2007-003",
          "refsource" : "NETBSD",
          "tags" : [ ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01070495",
          "name" : "SSRT061273",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/May/msg00004.html",
          "name" : "APPLE-SA-2007-05-24",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052018.html",
          "name" : "20070125 BIND remote exploit (low severity) [Fwd: Internet Systems Consortium Security Advisory.]",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html",
          "name" : "SUSE-SA:2007:014",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bind-announce&m=116968519321296&w=2",
          "name" : "[bind-announce] 20070125 Internet Systems Consortium Security Advisory.",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23904",
          "name" : "23904",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23924",
          "name" : "23924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23943",
          "name" : "23943",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23972",
          "name" : "23972",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23974",
          "name" : "23974",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23977",
          "name" : "23977",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24014",
          "name" : "24014",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24048",
          "name" : "24048",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24054",
          "name" : "24054",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24129",
          "name" : "24129",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24203",
          "name" : "24203",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24930",
          "name" : "24930",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24950",
          "name" : "24950",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25402",
          "name" : "25402",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25649",
          "name" : "25649",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc",
          "name" : "FreeBSD-SA-07:02",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200702-06.xml",
          "name" : "GLSA-200702-06",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017561",
          "name" : "1017561",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.494157",
          "name" : "SSA:2007-026-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.isc.org/index.pl?/sw/bind/bind-security.php",
          "name" : "http://www.isc.org/index.pl?/sw/bind/bind-security.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8",
          "name" : "http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4",
          "name" : "http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:030",
          "name" : "MDKSA-2007:030",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.html",
          "name" : "OpenPKG-SA-2007.007",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0057.html",
          "name" : "RHSA-2007:0057",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458066/100/0/threaded",
          "name" : "20070125 BIND remote exploit (low severity) [Fwd: Internet Systems Consortium Security Advisory.]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22229",
          "name" : "22229",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0005",
          "name" : "2007-0005",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-418-1",
          "name" : "USN-418-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0349",
          "name" : "ADV-2007-0349",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1401",
          "name" : "ADV-2007-1401",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1939",
          "name" : "ADV-2007-1939",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2163",
          "name" : "ADV-2007-2163",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2315",
          "name" : "ADV-2007-2315",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488",
          "name" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-989",
          "name" : "https://issues.rpath.com/browse/RPL-989",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9614",
          "name" : "oval:org.mitre.oval:def:9614",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144",
          "name" : "SSRT071304",
          "refsource" : "HP",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to \"dereference a freed fetch context.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.4.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T20:28Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0494",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "isc",
            "product" : {
              "product_data" : [ {
                "product_name" : "bind",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-19"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc",
          "name" : "20070201-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=305530",
          "name" : "http://docs.info.apple.com/article.html?artnum=305530",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2507",
          "name" : "FEDORA-2007-147",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2537",
          "name" : "FEDORA-2007-164",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc",
          "name" : "NetBSD-SA2007-003",
          "refsource" : "NETBSD",
          "tags" : [ ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01070495",
          "name" : "SSRT061273",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/May/msg00004.html",
          "name" : "APPLE-SA-2007-05-24",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html",
          "name" : "20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html",
          "name" : "SUSE-SA:2007:014",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bind-announce&m=116968519300764&w=2",
          "name" : "[bind-announce] 20070125 Internet Systems Consortium Security Advisory.",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23904",
          "name" : "23904",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23924",
          "name" : "23924",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23943",
          "name" : "23943",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23944",
          "name" : "23944",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23972",
          "name" : "23972",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23974",
          "name" : "23974",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23977",
          "name" : "23977",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24014",
          "name" : "24014",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24048",
          "name" : "24048",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24054",
          "name" : "24054",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24083",
          "name" : "24083",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24129",
          "name" : "24129",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24203",
          "name" : "24203",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24284",
          "name" : "24284",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24648",
          "name" : "24648",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24930",
          "name" : "24930",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24950",
          "name" : "24950",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25402",
          "name" : "25402",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25482",
          "name" : "25482",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25649",
          "name" : "25649",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25715",
          "name" : "25715",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26909",
          "name" : "26909",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/27706",
          "name" : "27706",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc",
          "name" : "FreeBSD-SA-07:02",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200702-06.xml",
          "name" : "GLSA-200702-06",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017573",
          "name" : "1017573",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.494157",
          "name" : "SSA:2007-026-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102969-1",
          "name" : "102969",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-125.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-125.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1254",
          "name" : "DSA-1254",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.isc.org/index.pl?/sw/bind/bind-security.php",
          "name" : "http://www.isc.org/index.pl?/sw/bind/bind-security.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8",
          "name" : "http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4",
          "name" : "http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:030",
          "name" : "MDKSA-2007:030",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.html",
          "name" : "OpenPKG-SA-2007.007",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0044.html",
          "name" : "RHSA-2007:0044",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0057.html",
          "name" : "RHSA-2007:0057",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22231",
          "name" : "22231",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0005",
          "name" : "2007-0005",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-418-1",
          "name" : "USN-418-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1401",
          "name" : "ADV-2007-1401",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1939",
          "name" : "ADV-2007-1939",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2002",
          "name" : "ADV-2007-2002",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2163",
          "name" : "ADV-2007-2163",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2245",
          "name" : "ADV-2007-2245",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2315",
          "name" : "ADV-2007-2315",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/3229",
          "name" : "ADV-2007-3229",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IY95618",
          "name" : "IY95618",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IY95619",
          "name" : "IY95619",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IY96144",
          "name" : "IY96144",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IY96324",
          "name" : "IY96324",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31838",
          "name" : "bind-rrsets-dos(31838)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488",
          "name" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-989",
          "name" : "https://issues.rpath.com/browse/RPL-989",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11523",
          "name" : "oval:org.mitre.oval:def:11523",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144",
          "name" : "SSRT071304",
          "refsource" : "HP",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the \"DNSSEC Validation\" vulnerability."
        }, {
          "lang" : "en",
          "value" : "Syccessful exploitation requires that the victim has enabled dnssec validation in named.conf by specifying trusted-keys."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.0.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.0.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.0.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.0.0:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.0.0:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.0.0:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.0.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.0.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.1:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.1:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.1:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.1:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.1:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.3:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.3:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.1.3:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:a1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:a2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:a3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:b1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:b2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:rc10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:rc8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.0:rc9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.2:p2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.2:p3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.3:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.3:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.3:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.3:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.4:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.4:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.4:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.4:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.4:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.4:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.4:rc8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.5:b2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.5:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.2.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.0:b2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.0:b3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.0:b4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.0:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.1:b2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.3.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.4.0:a1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.4.0:a2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.4.0:a3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.4.0:a4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.4.0:a5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.4.0:b1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.4.0:b2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.4.0:b3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.4.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:9.5.0:a1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T20:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0495",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpsherpa",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpsherpa",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31599",
          "name" : "31599",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23817",
          "name" : "23817",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0263",
          "name" : "ADV-2007-0263",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3161",
          "name" : "3161",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpsherpa:phpsherpa:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T21:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0496",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "neon_labs",
            "product" : {
              "product_data" : [ {
                "product_name" : "neon_labs_website",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36797",
          "name" : "36797",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0268",
          "name" : "ADV-2007-0268",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3163",
          "name" : "3163",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:neon_labs:neon_labs_website:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T21:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0497",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "upload-service",
            "product" : {
              "product_data" : [ {
                "product_name" : "upload-service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://echo.or.id/adv/adv62-y3dips-2007.txt",
          "name" : "http://echo.or.id/adv/adv62-y3dips-2007.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32938",
          "name" : "32938",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23845",
          "name" : "23845",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457800/100/100/threaded",
          "name" : "20070123 [ECHO_ADV_62$2007] Upload Service 1.0 remote file inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22189",
          "name" : "22189",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0265",
          "name" : "ADV-2007-0265",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31634",
          "name" : "uploadservice-top-file-include(31634)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the maindir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:upload-service:upload-service:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0498",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sky_gunning",
            "product" : {
              "product_data" : [ {
                "product_name" : "myspeach",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31603",
          "name" : "31603",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3165",
          "name" : "3165",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sky_gunning:myspeach:2.1_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T21:28Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0499",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sangwan_kim",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpindexpage",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33014",
          "name" : "33014",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23992",
          "name" : "23992",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22161",
          "name" : "22161",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0267",
          "name" : "ADV-2007-0267",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3164",
          "name" : "3164",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sangwan_kim:phpindexpage:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T21:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0500",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bradabra",
            "product" : {
              "product_data" : [ {
                "product_name" : "bradabra",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31604",
          "name" : "31604",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23851",
          "name" : "23851",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0264",
          "name" : "ADV-2007-0264",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3162",
          "name" : "3162",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bradabra:bradabra:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T21:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0501",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mafia_scum_tools",
            "product" : {
              "product_data" : [ {
                "product_name" : "mafia_scum_tools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36810",
          "name" : "36810",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22151",
          "name" : "22151",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0271",
          "name" : "ADV-2007-0271",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31637",
          "name" : "mafiascum-index-file-include(31637)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3171",
          "name" : "3171",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows remote attackers to execute arbitrary PHP code via a URL in the gen parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mafia_scum_tools:mafia_scum_tools:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T21:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0502",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webspell",
            "product" : {
              "product_data" : [ {
                "product_name" : "webspell",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.01.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36798",
          "name" : "36798",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22149",
          "name" : "22149",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0270",
          "name" : "ADV-2007-0270",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31632",
          "name" : "webspell-gallery-sql-injection(31632)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3172",
          "name" : "3172",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webspell:webspell:4.01.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T21:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0503",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sunos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31598",
          "name" : "31598",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23885",
          "name" : "23885",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017541",
          "name" : "1017541",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102728-1",
          "name" : "102728",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-040.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-040.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22175",
          "name" : "22175",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0287",
          "name" : "ADV-2007-0287",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31668",
          "name" : "solaris-kcmscalibrate-privilege-escalation(31668)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1495",
          "name" : "oval:org.mitre.oval:def:1495",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local users to execute arbitrary commands via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-25T21:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0504",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vote_pro",
            "product" : {
              "product_data" : [ {
                "product_name" : "vote_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31606",
          "name" : "31606",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23834",
          "name" : "23834",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0300",
          "name" : "ADV-2007-0300",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3180",
          "name" : "3180",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is supplied to an eval function call, a different vulnerability type than CVE-2005-4632."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vote_pro:vote_pro:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0505",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "project",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6_1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "project_issue_tracking_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/112146",
          "name" : "http://drupal.org/node/112146",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32134",
          "name" : "32134",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23887",
          "name" : "23887",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22224",
          "name" : "22224",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0312",
          "name" : "ADV-2007-0312",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31729",
          "name" : "projecttracking-extension-file-upload(31729)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:4.6_1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:4.7_1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:4.7_2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:5.0:*:dev:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:4.7_1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:4.7_2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:5.0:*:dev:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 8.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 6.8,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0506",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "project",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6_1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "project_issue_tracking_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/112146",
          "name" : "http://drupal.org/node/112146",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32135",
          "name" : "32135",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23887",
          "name" : "23887",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22224",
          "name" : "22224",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0312",
          "name" : "ADV-2007-0312",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31727",
          "name" : "projecttracking-access-info-disclosure(31727)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:4.6_1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:4.7_1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:4.7_2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:5.0:*:dev:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:4.7_1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:4.7_2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:5.0:*:dev:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0507",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "acidfree",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6_1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/112145",
          "name" : "http://drupal.org/node/112145",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32132",
          "name" : "32132",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23895",
          "name" : "23895",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22202",
          "name" : "22202",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0313",
          "name" : "ADV-2007-0313",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31724",
          "name" : "acidfree-albums-sql-injection(31724)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with \"create acidfree albums\" privileges to execute arbitrary SQL commands via node titles."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:acidfree:4.6_1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:acidfree:4.7_1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0508",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bbclone",
            "product" : {
              "product_data" : [ {
                "product_name" : "bbclone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.31",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32957",
          "name" : "32957",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23874",
          "name" : "23874",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0318",
          "name" : "ADV-2007-0318",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3183",
          "name" : "3183",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the BBC_LANGUAGE_PATH parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bbclone:bbclone:0.31:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0509",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "maklerplus",
            "product" : {
              "product_data" : [ {
                "product_name" : "maklerplus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32950",
          "name" : "32950",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23864",
          "name" : "23864",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=479940",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=479940",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22206",
          "name" : "22206",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0321",
          "name" : "ADV-2007-0321",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31734",
          "name" : "maklerplus-multiple-unspecified(31734)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in MaklerPlus before 1.2 have unknown impact and attack vectors, possibly relating to cross-site scripting (XSS) in the slogan parameter in main.tpl, or information leaks in error messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maklerplus:maklerplus:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maklerplus:maklerplus:1.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0510",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "awffull",
            "product" : {
              "product_data" : [ {
                "product_name" : "awffull",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.7.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32956",
          "name" : "32956",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23831",
          "name" : "23831",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.stedee.id.au/awffull#changes",
          "name" : "http://www.stedee.id.au/awffull#changes",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.stedee.id.au/pipermail/awffull_stedee.id.au/2007-January/000309.html",
          "name" : "[AWFFULL] 20070123 Regarding the fixes in 3.7.2",
          "refsource" : "MLIST",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0320",
          "name" : "ADV-2007-0320",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31731",
          "name" : "awffull-multiple-bo(31731)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in (1) graphs.c, (2) output.c, and (3) preserve.c in AWFFull 3.7.1 and earlier have unknown impact and attack vectors.  NOTE: some of these details are obtained from third party information.  NOTE: There may not be any attack vector that crosses privilege boundaries."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:awffull:awffull:3.7.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0511",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpxmldom",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpxmldom",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32953",
          "name" : "32953",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32954",
          "name" : "32954",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32955",
          "name" : "32955",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23875",
          "name" : "23875",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22201",
          "name" : "22201",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0309",
          "name" : "ADV-2007-0309",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31726",
          "name" : "phpxd-path-file-include(31726)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3184",
          "name" : "3184",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) dom.php, (2) dtd.php, or (3) parser.php in include/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpxmldom:phpxmldom:0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0512",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hitachi",
            "product" : {
              "product_data" : [ {
                "product_name" : "tpi_link",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "03_04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "03_06_k",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "05_00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "05_03_f",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "tpi_server_base",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "03_01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "03_01_db",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "03_01_e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "03_01_fd",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "05_00_h",
                    "version_affected" : "="
                  }, {
                    "version_value" : "05_03",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32962",
          "name" : "32962",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23866",
          "name" : "23866",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-021_e/01-e.html",
          "name" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-021_e/01-e.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22223",
          "name" : "22223",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0325",
          "name" : "ADV-2007-0325",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Hitachi TP1/LiNK 05-00 through 05-03-/F, 03-04 through 03-06-/K, and 03-00 through 03-03-/H; and TP1/Server Base 05-00 through 05-00-/M, 03-01-E through 03-01-FD, 03-01 through 03-01-DB, and 05-03; allow attackers to cause a denial of service (process crash) via invalid data to an OpenTP1 port."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:tpi_link:03_04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:tpi_link:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "03_06_k"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:tpi_link:05_00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:tpi_link:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "05_03_f"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:tpi_server_base:03_01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:tpi_server_base:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "03_01_db"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:tpi_server_base:03_01_e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:tpi_server_base:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "03_01_fd"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:tpi_server_base:05_00_h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:tpi_server_base:05_03:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0513",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hitachi",
            "product" : {
              "product_data" : [ {
                "product_name" : "hirdb_parallel_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "hirdb_single_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "hirdb_single_server_workgroup_edition",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "hirdb_workgroup_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "hirdb_datareplicator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0_64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6_64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7_64",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32996",
          "name" : "32996",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23816",
          "name" : "23816",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-023_e/01-e.html",
          "name" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-023_e/01-e.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22244",
          "name" : "22244",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0327",
          "name" : "ADV-2007-0327",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31735",
          "name" : "hitachi-hirdb-request-dos(31735)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Hitachi HiRDB Datareplicator 7HiRDB, 7(64), 6, 6(64), 5.0, and 5.0(64); and various products that bundle HiRDB Datareplicator; allows attackers to cause a denial of service (CPU consumption) via certain data."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hirdb_parallel_server:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hirdb_parallel_server:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hirdb_parallel_server:6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hirdb_parallel_server:7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hirdb_single_server:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hirdb_single_server:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hirdb_single_server:6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hirdb_single_server:7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hirdb_single_server_workgroup_edition:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hirdb_workgroup_server:6:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hitachi:hirdb_datareplicator:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hitachi:hirdb_datareplicator:5.0_64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hitachi:hirdb_datareplicator:6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hitachi:hirdb_datareplicator:6_64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hitachi:hirdb_datareplicator:7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hitachi:hirdb_datareplicator:7_64:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0514",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hitachi",
            "product" : {
              "product_data" : [ {
                "product_name" : "cosminexus_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cosminexus_application_server_version_5",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cosminexus_developer_light_version_6",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cosminexus_developer_professional_version_6",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cosminexus_developer_standard_version_6",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cosminexus_developer_version_5",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cosminexus_server_-_enterprise_edition",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cosminexus_server_-_standard_edition",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cosminexus_server_-_standard_edition_version_4",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cosminexus_server_-_web_edition",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cosminexus_server_-_web_edition_version_4",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "hitachi_web_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ucosminexus_application_server_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ucosminexus_application_server_smart_edition",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ucosminexus_application_server_standard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ucosminexus_developer_light",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ucosminexus_developer_standard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ucosminexus_service_architect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ucosminexus_service_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32997",
          "name" : "32997",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32998",
          "name" : "32998",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23843",
          "name" : "23843",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-022_e/01-e.html",
          "name" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-022_e/01-e.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0326",
          "name" : "ADV-2007-0326",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:cosminexus_application_server:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:cosminexus_application_server:6:*:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:cosminexus_application_server_version_5:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:cosminexus_developer_light_version_6:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:cosminexus_developer_professional_version_6:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:cosminexus_developer_standard_version_6:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:cosminexus_developer_version_5:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:cosminexus_server_-_enterprise_edition:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:cosminexus_server_-_standard_edition:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:cosminexus_server_-_standard_edition_version_4:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:cosminexus_server_-_web_edition:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:cosminexus_server_-_web_edition_version_4:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hitachi_web_server:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:ucosminexus_application_server_enterprise:*:*:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:ucosminexus_application_server_smart_edition:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:ucosminexus_application_server_standard:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:ucosminexus_developer_light:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:ucosminexus_developer_standard:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:ucosminexus_service_architect:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:ucosminexus_service_platform:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0515",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://isc.sans.org/diary.html?storyid=2133",
          "name" : "http://isc.sans.org/diary.html?storyid=2133",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31900",
          "name" : "31900",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23950",
          "name" : "23950",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017564",
          "name" : "1017564",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/412225",
          "name" : "VU#412225",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.microsoft.com/technet/security/advisory/932114.mspx",
          "name" : "http://www.microsoft.com/technet/security/advisory/932114.mspx",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22225",
          "name" : "22225",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22328",
          "name" : "22328",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/enterprise/security_response/weblog/2007/01/multiple_organizations_targett.html",
          "name" : "http://www.symantec.com/enterprise/security_response/weblog/2007/01/multiple_organizations_targett.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/enterprise/security_response/weblog/2007/01/new_microsoft_word_2000_vulner.html",
          "name" : "http://www.symantec.com/enterprise/security_response/weblog/2007/01/new_microsoft_word_2000_vulner.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-013010-5422-99&tabid=2",
          "name" : "http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-013010-5422-99&tabid=2",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
          "name" : "TA07-044A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0350",
          "name" : "ADV-2007-0350",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014",
          "name" : "MS07-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31834",
          "name" : "word-document-code-execution(31834)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A528",
          "name" : "oval:org.mitre.oval:def:528",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2006:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-26T00:28Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0516",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "yana_framework",
            "product" : {
              "product_data" : [ {
                "product_name" : "yana_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.3a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.4a",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://all-community.de/pub/pages/changes.php?language=en",
          "name" : "http://all-community.de/pub/pages/changes.php?language=en",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/23855",
          "name" : "23855",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/31615",
          "name" : "31615",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31671",
          "name" : "yana-unspecified-security-bypass(31671)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Yana Framework before 2.8.5a allows remote authenticated users with permissions to modify a guestbook profile to modify or delete arbitrary guestbook profiles via unspecified vectors.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yana_framework:yana_framework:2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yana_framework:yana_framework:2.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yana_framework:yana_framework:2.8.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yana_framework:yana_framework:2.8.3a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yana_framework:yana_framework:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.8.4a"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0517",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scriptsez",
            "product" : {
              "product_data" : [ {
                "product_name" : "random_php_quote",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32947",
          "name" : "32947",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23888",
          "name" : "23888",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2184",
          "name" : "2184",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457825/100/0/threaded",
          "name" : "20070123 RANDOM PHP QUOTE 1.0 (pwd.txt) Remote Password Disclosur",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31696",
          "name" : "randomphpquote-pwd-information-disclosure(31696)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Scriptsez Random PHP Quote 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password information via a direct request for pwd.txt."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scriptsez:random_php_quote:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0518",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scriptsez",
            "product" : {
              "product_data" : [ {
                "product_name" : "smart_php_subscriber",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32946",
          "name" : "32946",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23886",
          "name" : "23886",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2183",
          "name" : "2183",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457852/100/0/threaded",
          "name" : "20070123 subscribe (pwd.txt) Remote Password Disclosur",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31701",
          "name" : "subscriber-pwd-information-disclosure(31701)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scriptsez:smart_php_subscriber:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0519",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xmb_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "u2u_instant_messenger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aria-security.com/forum/showthread.php?p=129",
          "name" : "http://aria-security.com/forum/showthread.php?p=129",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2182",
          "name" : "2182",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457630/100/0/threaded",
          "name" : "20070120 XMB \"U2U Instant Messenger\" Cross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31661",
          "name" : "u2u-memcp-xss(31661)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xmb_software:u2u_instant_messenger:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0520",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "unique_ads",
            "product" : {
              "product_data" : [ {
                "product_name" : "unique_ads",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2181",
          "name" : "2181",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457667/100/0/threaded",
          "name" : "20070121 SQL Injection in Unique Ads ( UDS )",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31660",
          "name" : "uniqueads-banner-sql-injection(31660)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in banner.php in Unique Ads (UDS) 1.x allows remote attackers to execute arbitrary SQL commands via the bid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:unique_ads:unique_ads:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0521",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sony_ericsson",
            "product" : {
              "product_data" : [ {
                "product_name" : "k700i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "w810i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2180",
          "name" : "2180",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457768/100/0/threaded",
          "name" : "20070123 Bluetooth DoS by obex push",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457797/100/0/threaded",
          "name" : "20070123 Re: Bluetooth DoS by obex push [readable]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Sony Ericsson K700i and W810i phones allow remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:sony_ericsson:k700i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:sony_ericsson:w810i:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:A/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "ADJACENT_NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.3
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.5,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0522",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "motorola",
            "product" : {
              "product_data" : [ {
                "product_name" : "motorazr",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "v3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2180",
          "name" : "2180",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457768/100/0/threaded",
          "name" : "20070123 Bluetooth DoS by obex push",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457797/100/0/threaded",
          "name" : "20070123 Re: Bluetooth DoS by obex push [readable]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Motorola MOTORAZR V3 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:motorola:motorazr:v3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:A/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "ADJACENT_NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.3
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.5,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0523",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nokia",
            "product" : {
              "product_data" : [ {
                "product_name" : "n70",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2180",
          "name" : "2180",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457768/100/0/threaded",
          "name" : "20070123 Bluetooth DoS by obex push",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457797/100/0/threaded",
          "name" : "20070123 Re: Bluetooth DoS by obex push [readable]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Nokia N70 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:nokia:n70:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:A/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "ADJACENT_NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.3
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.5,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0524",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lg_electronics",
            "product" : {
              "product_data" : [ {
                "product_name" : "chocolate_kg800",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2180",
          "name" : "2180",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457768/100/0/threaded",
          "name" : "20070123 Bluetooth DoS by obex push",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457797/100/0/threaded",
          "name" : "20070123 Re: Bluetooth DoS by obex push [readable]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The LG Chocolate KG800 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:lg_electronics:chocolate_kg800:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:A/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "ADJACENT_NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 5.5,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0525",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "grigoriadis",
            "product" : {
              "product_data" : [ {
                "product_name" : "mini_web_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.04",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33512",
          "name" : "33512",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=479480&group_id=187000",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=479480&group_id=187000",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0294",
          "name" : "ADV-2007-0294",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in Nickolas Grigoriadis Mini Web server (MiniWebsvr) before 0.05 have unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grigoriadis:mini_web_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.04"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0526",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bitweaver",
            "product" : {
              "product_data" : [ {
                "product_name" : "bitweaver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33578",
          "name" : "33578",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33579",
          "name" : "33579",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33580",
          "name" : "33580",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33581",
          "name" : "33581",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2186",
          "name" : "2186",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457695/100/0/threaded",
          "name" : "20070122 [x0n3-h4ck] bitweaver 1.3.1 XSS Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31655",
          "name" : "bitweaver-multiple-scripts-xss(31655)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the URL (PATH_INFO) to (1) articles/edit.php, (2) articles/list.php, (3) blogs/list_blogs.php, or (4) blogs/rankings.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bitweaver:bitweaver:1.3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0527",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "website_baker",
            "product" : {
              "product_data" : [ {
                "product_name" : "website_baker",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32945",
          "name" : "32945",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23828",
          "name" : "23828",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2185",
          "name" : "2185",
          "refsource" : "SREASON",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457684/100/0/threaded",
          "name" : "20070122 SQL Injection by using Cookie Poisoning for Website Baker Version 2.6.5 and before",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22176",
          "name" : "22176",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0311",
          "name" : "ADV-2007-0311",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31692",
          "name" : "websitebaker-login-sql-injection(31692)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the is_remembered function in class.login.php in Website Baker 2.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the REMEMBER_KEY cookie parameter. NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:website_baker:website_baker:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.6.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0528",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "centrality_communications",
            "product" : {
              "product_data" : [ {
                "product_name" : "pa168_chipset",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "firmware_1.54",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32966",
          "name" : "32966",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23919",
          "name" : "23919",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23936",
          "name" : "23936",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.procheckup.com/Vulner_PR0614.php",
          "name" : "http://www.procheckup.com/Vulner_PR0614.php",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457868/100/0/threaded",
          "name" : "20070123 PR06-14: IP Phones based on Centrality Communications/Aredfox PA168 chipset weak session management vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0346",
          "name" : "ADV-2007-0346",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3189",
          "name" : "3189",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:centrality_communications:pa168_chipset:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "firmware_1.54"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0529",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php_link_directory",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_link_directory",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32952",
          "name" : "32952",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457672/100/0/threaded",
          "name" : "20070121 PHP Link Directory XSS Vulnerability version <= 3.0.6",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.smilehouse.com/advisory/phplinkdirectory_070121.txt",
          "name" : "http://www.smilehouse.com/advisory/phplinkdirectory_070121.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31662",
          "name" : "phpld-admin-xss(31662)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.html (aka the administration page) in PHP Link Directory (phpLD) 3.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted link, which is triggered when the administrator uses the \"Validate Links\" functionality."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_link_directory:php_link_directory:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0530",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "advanced_guestbook",
            "product" : {
              "product_data" : [ {
                "product_name" : "advanced_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/457870/100/0/threaded",
          "name" : "20070123 Advanced Guestbook <=- 2.4.2 (include_path) Remote File Include Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457955/100/0/threaded",
          "name" : "20070123 Re: Advanced Guestbook <=- 2.4.2 (include_path) Remote File Include Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in Advanced Guestbook 2.4.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) index.php, (2) addentry.php, or (3) picture.php, a different set of vectors than CVE-2006-5804.  NOTE: this issue has been disputed by third party researchers, stating that the include_path variable is instantiated before use."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:advanced_guestbook:advanced_guestbook:2.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0531",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freewebshop",
            "product" : {
              "product_data" : [ {
                "product_name" : "freewebshop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://14house.blogspot.com/2007/01/freewebshoporg-remote-file-inclusion.html",
          "name" : "http://14house.blogspot.com/2007/01/freewebshoporg-remote-file-inclusion.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32951",
          "name" : "32951",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23898",
          "name" : "23898",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017549",
          "name" : "1017549",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.freewebshop.org/?id=36",
          "name" : "http://www.freewebshop.org/?id=36",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0319",
          "name" : "ADV-2007-0319",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31732",
          "name" : "freewebshop-login-file-include(31732)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in includes/login.php in FreeWebShop 2.2.3 and 2.2.4 before 20070123 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freewebshop:freewebshop:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freewebshop:freewebshop:2.2.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0532",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tuan_do",
            "product" : {
              "product_data" : [ {
                "product_name" : "uploader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6_beta_1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2187",
          "name" : "2187",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457698/100/0/threaded",
          "name" : "20070122 Uploader <= (userdata/user_1.txt) Password Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31683",
          "name" : "uploader-userdata-info-disclosure(31683)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Tuan Do Uploader (aka php-uploader) 6 beta 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrator password hash via a direct request for userdata/user_1.txt."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tuan_do:uploader:6_beta_1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0533",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "atozed_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "intraweb_component",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.atozed.com/Olaf/20070124.en.aspx",
          "name" : "http://blogs.atozed.com/Olaf/20070124.en.aspx",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://blogs.atozed.com/Olaf/20070124A.en.aspx",
          "name" : "http://blogs.atozed.com/Olaf/20070124A.en.aspx",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32973",
          "name" : "32973",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23902",
          "name" : "23902",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457758/100/0/threaded",
          "name" : "20070123 AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457947/100/0/threaded",
          "name" : "20070124 Re: AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458121/100/0/threaded",
          "name" : "20070125 Re: AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22185",
          "name" : "22185",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0355",
          "name" : "ADV-2007-0355",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31685",
          "name" : "intraweb-component-dos(31685)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The AToZed IntraWeb component 8.0 and earlier for Borland Delphi and Kylix, and IntraWeb 9.0 before build (9.0.12), allows remote attackers to cause a denial of service (thread hang or CPU consumption) via a crafted HTTP request, related to the OnBeforeDispatch function in the TIWServerController object."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atozed_software:intraweb_component:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atozed_software:intraweb_component:9.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0534",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "project",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "project_issue_tracking_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://drupal.org/node/112146",
          "name" : "http://drupal.org/node/112146",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32133",
          "name" : "32133",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23908",
          "name" : "23908",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22224",
          "name" : "22224",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0312",
          "name" : "ADV-2007-0312",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31728",
          "name" : "projecttracking-unspecified-xss(31728)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in the (1) Project issue tracking 4.7.0 through 5.x before 20070123 and (2) Project 4.6.0 through 5.x before 20070123 modules for Drupal allow remote authenticated users to inject arbitrary web script or HTML via (a) certain \"fields on project nodes\" or (b) \"certain project-specific settings regarding issue tracking.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:4.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:4.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:project_issue_tracking_module:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0535",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vote_pro",
            "product" : {
              "product_data" : [ {
                "product_name" : "vote_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31606",
          "name" : "31606",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23834",
          "name" : "23834",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0300",
          "name" : "ADV-2007-0300",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitrary code via requests to unspecified PHP scripts with the poll_id parameter, which is supplied to eval function calls, a different set of vectors than CVE-2007-0504.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vote_pro:vote_pro:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-26T01:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0536",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rpath",
            "product" : {
              "product_data" : [ {
                "product_name" : "rpath_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.rpath.com/pipermail/security-announce/2007-January/000137.html",
          "name" : "http://lists.rpath.com/pipermail/security-announce/2007-January/000137.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32972",
          "name" : "32972",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23922",
          "name" : "23922",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31942",
          "name" : "rpath-rmake-privilege-escalation(31942)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-987",
          "name" : "https://issues.rpath.com/browse/RPL-987",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissions and might allow local users to gain privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:rpath:rpath_linux:1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-27T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0537",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kde",
            "product" : {
              "product_data" : [ {
                "product_name" : "konqueror",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32975",
          "name" : "32975",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23932",
          "name" : "23932",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24013",
          "name" : "24013",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24065",
          "name" : "24065",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24442",
          "name" : "24442",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24463",
          "name" : "24463",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24889",
          "name" : "24889",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/27108",
          "name" : "27108",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017591",
          "name" : "1017591",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-10.xml",
          "name" : "GLSA-200703-10",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kde.org/info/security/advisory-20070206-1.txt",
          "name" : "http://www.kde.org/info/security/advisory-20070206-1.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:031",
          "name" : "MDKSA-2007:031",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:157",
          "name" : "MDKSA-2007:157",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_6_sr.html",
          "name" : "SUSE-SR:2007:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0909.html",
          "name" : "RHSA-2007:0909",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457924/100/0/threaded",
          "name" : "20070124 Re: Safari Improperly Parses HTML Documents & BlogSpot XSS vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22428",
          "name" : "22428",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-420-1",
          "name" : "USN-420-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0505",
          "name" : "ADV-2007-0505",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1117",
          "name" : "https://issues.rpath.com/browse/RPL-1117",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10244",
          "name" : "oval:org.mitre.oval:def:10244",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kde:konqueror:3.5.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-29T16:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0538",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "telligent_systems",
            "product" : {
              "product_data" : [ {
                "product_name" : "community_server_forums",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33583",
          "name" : "33583",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33584",
          "name" : "33584",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2211",
          "name" : "2211",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457996/100/0/threaded",
          "name" : "20070124 Weaknesses in Pingback Design",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457999/100/0/threaded",
          "name" : "20070124 DoS against Telligent Community Server",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Telligent Community Server 2.1 and earlier allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to (1) a large file, which triggers a long download session without a timeout constraint; or (2) a file with a binary content type, which is downloaded even though it cannot contain usable pingback data."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:telligent_systems:community_server_forums:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0539",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2191",
          "name" : "2191",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457996/100/0/threaded",
          "name" : "20070124 Weaknesses in Pingback Design",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458003/100/0/threaded",
          "name" : "20070124 Multiple Remote Vulnerabilities in Wordpress",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0540",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/30013",
          "name" : "30013",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2191",
          "name" : "2191",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2008/dsa-1564",
          "name" : "DSA-1564",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457996/100/0/threaded",
          "name" : "20070124 Weaknesses in Pingback Design",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458003/100/0/threaded",
          "name" : "20070124 Multiple Remote Vulnerabilities in Wordpress",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0541",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2191",
          "name" : "2191",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457996/100/0/threaded",
          "name" : "20070124 Weaknesses in Pingback Design",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458003/100/0/threaded",
          "name" : "20070124 Multiple Remote Vulnerabilities in Wordpress",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0542",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "212cafe",
            "product" : {
              "product_data" : [ {
                "product_name" : "guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.00_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2190",
          "name" : "2190",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457660/100/0/threaded",
          "name" : "20070121 XSS in Guestbook ( v.4.00 beta )",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31663",
          "name" : "guestbook-show-xss(31663)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in show.php in 212cafe Guestbook 4.00 beta allows remote attackers to inject arbitrary web script or HTML via the user parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:212cafe:guestbook:4.00_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0543",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zixforum",
            "product" : {
              "product_data" : [ {
                "product_name" : "zixforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.14",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2189",
          "name" : "2189",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457950/100/0/threaded",
          "name" : "20070124 ZixForum <= 1.14 (Zixforum.mdb) Remote Password Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458135/100/100/threaded",
          "name" : "20070124 Re: ZixForum <= 1.14 (Zixforum.mdb) Remote Password Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ZixForum 1.14 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for Zixforum.mdb.  NOTE: a followup post suggests that this issue only occurs if the administrator does not properly follow installation directions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zixforum:zixforum:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.14"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "NONE",
          "baseScore" : 9.4
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0544",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32967",
          "name" : "32967",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23934",
          "name" : "23934",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28837",
          "name" : "28837",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457929/100/0/threaded",
          "name" : "20070124 [Aria-Security Team] MyBB Cross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22205",
          "name" : "22205",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31740",
          "name" : "mybb-subject-field-xss(31740)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in private.php in MyBB (aka MyBulletinBoard) allows remote authenticated users to inject arbitrary web script or HTML via the Subject field, a different vector than CVE-2006-2949."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:1.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0545",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "maxtricity",
            "product" : {
              "product_data" : [ {
                "product_name" : "tagger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33577",
          "name" : "33577",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2214",
          "name" : "2214",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457953/100/0/threaded",
          "name" : "20070124 Maxtricity Tagger Password Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Maxtricity Tagger 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for tagger.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maxtricity:tagger:0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0546",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "toxiclab",
            "product" : {
              "product_data" : [ {
                "product_name" : "shoutbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33576",
          "name" : "33576",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2213",
          "name" : "2213",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457931/100/0/threaded",
          "name" : "20070124 Toxiclab Shoutbox Password Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Toxiclab Shoutbox 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db.mdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toxiclab:shoutbox:1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0547",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cgi-rescue",
            "product" : {
              "product_data" : [ {
                "product_name" : "webform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/jp/JVN%2305123538/index.html",
          "name" : "JVN#05123538",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32964",
          "name" : "32964",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23913",
          "name" : "23913",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0344",
          "name" : "ADV-2007-0344",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in CGI-RESCUE WebFORM 4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cgi-rescue:webform:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0548",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "karjasoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "sami_http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31623",
          "name" : "31623",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23901",
          "name" : "23901",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31690",
          "name" : "sami-http-request-dos(31690)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3182",
          "name" : "3182",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent objects."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:karjasoft:sami_http_server:2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0549",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "212cafe",
            "product" : {
              "product_data" : [ {
                "product_name" : "212cafeboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.30_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2212",
          "name" : "2212",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457611/100/0/threaded",
          "name" : "20070121 XSS in 212cafeBoard ( Verision 0.08 & 6.30 Beta )",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31650",
          "name" : "212cafeboard-list3-xss(31650)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in list3.php in 212cafeBoard 6.30 Beta allows remote attackers to inject arbitrary web script or HTML via the user parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:212cafe:212cafeboard:6.30_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0550",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "212cafe",
            "product" : {
              "product_data" : [ {
                "product_name" : "212cafeboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.08_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2212",
          "name" : "2212",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457611/100/0/threaded",
          "name" : "20070121 XSS in 212cafeBoard ( Verision 0.08 & 6.30 Beta )",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31651",
          "name" : "212cafeboard-search-xss(31651)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.php in 212cafeBoard 0.08 Beta allows remote attackers to inject arbitrary web script or HTML via keyword parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:212cafe:212cafeboard:0.08_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0551",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cmsmadesimple",
            "product" : {
              "product_data" : [ {
                "product_name" : "cms_made_simple",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33572",
          "name" : "33572",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2195",
          "name" : "2195",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/457668/100/0/threaded",
          "name" : "20070120 cmsimple 2.7 Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31658",
          "name" : "cmsimple-cms-file-include(31658)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in cmsimple/cms.php in CMSimple 2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pth[file][config] and (2) pth[file][image] parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cmsmadesimple:cms_made_simple:2.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0552",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oh_no_not_another_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "oh_no_not_another_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.0.8.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://onnac.svn.sourceforge.net/viewvc/onnac/trunk/install/default/error404.html?view=log",
          "name" : "http://onnac.svn.sourceforge.net/viewvc/onnac/trunk/install/default/error404.html?view=log",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/36811",
          "name" : "36811",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/forum/forum.php?forum_id=655260",
          "name" : "http://sourceforge.net/forum/forum.php?forum_id=655260",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22256",
          "name" : "22256",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0347",
          "name" : "ADV-2007-0347",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31795",
          "name" : "onnac-error-xss(31795)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in install/default/error404.html in Oh no! Not another CMS (Onnac) 0.0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the error_url parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oh_no_not_another_cms:oh_no_not_another_cms:0.0.8.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0553",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phproxy",
            "product" : {
              "product_data" : [ {
                "product_name" : "phproxy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36812",
          "name" : "36812",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=479999&group_id=110693",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=479999&group_id=110693",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22255",
          "name" : "22255",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0348",
          "name" : "ADV-2007-0348",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in index.inc.php in PHProxy before 0.5 beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) data[realm] and (2) _url parameters, different vectors than CVE-2004-2604.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phproxy:phproxy:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phproxy:phproxy:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phproxy:phproxy:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phproxy:phproxy:0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0554",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "guo_xu_guos_posting_system",
            "product" : {
              "product_data" : [ {
                "product_name" : "guo_xu_guos_posting_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31635",
          "name" : "31635",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23929",
          "name" : "23929",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2209",
          "name" : "2209",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458061/100/0/threaded",
          "name" : "20070125 GPS 1.2 Content Managing System (print.asp) Remote SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22232",
          "name" : "22232",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0353",
          "name" : "ADV-2007-0353",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31759",
          "name" : "gps-print-sql-injection(31759)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3195",
          "name" : "3195",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in print.asp in Guo Xu Guos Posting System (GPS) 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:guo_xu_guos_posting_system:guo_xu_guos_posting_system:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0555",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postgresql",
            "product" : {
              "product_data" : [ {
                "product_name" : "postgresql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc",
          "name" : "20070201-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2554",
          "name" : "FEDORA-2007-198",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.rpath.com/pipermail/security-announce/2007-February/000141.html",
          "name" : "[security-announce] 20070206 rPSA-2007-0025-1 postgresql postgresql-server",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33087",
          "name" : "33087",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24028",
          "name" : "24028",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24033",
          "name" : "24033",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24042",
          "name" : "24042",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24050",
          "name" : "24050",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24057",
          "name" : "24057",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24094",
          "name" : "24094",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24151",
          "name" : "24151",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24158",
          "name" : "24158",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24284",
          "name" : "24284",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24315",
          "name" : "24315",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24513",
          "name" : "24513",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24577",
          "name" : "24577",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25220",
          "name" : "25220",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-15.xml",
          "name" : "GLSA-200703-15",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017597",
          "name" : "1017597",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1",
          "name" : "102825",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1261",
          "name" : "DSA-1261",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:037",
          "name" : "MDKSA-2007:037",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_10_sr.html",
          "name" : "SUSE-SR:2007:010",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/support/security",
          "name" : "http://www.postgresql.org/support/security",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0064.html",
          "name" : "RHSA-2007:0064",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0067.html",
          "name" : "RHSA-2007:0067",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0068.html",
          "name" : "RHSA-2007:0068",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459280/100/0/threaded",
          "name" : "20070206 rPSA-2007-0025-1 postgresql postgresql-server",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459448/100/0/threaded",
          "name" : "20070208 rPSA-2007-0025-2 postgresql postgresql-server",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22387",
          "name" : "22387",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0007",
          "name" : "2007-0007",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-417-2",
          "name" : "USN-417-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0478",
          "name" : "ADV-2007-0478",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0774",
          "name" : "ADV-2007-0774",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32195",
          "name" : "postgresql-sqlfunctions-info-disclosure(32195)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1025",
          "name" : "https://issues.rpath.com/browse/RPL-1025",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-830",
          "name" : "https://issues.rpath.com/browse/RPL-830",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9739",
          "name" : "oval:org.mitre.oval:def:9739",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/417-1/",
          "name" : "USN-417-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 8.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0556",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postgresql",
            "product" : {
              "product_data" : [ {
                "product_name" : "postgresql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.09",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://fedoranews.org/cms/node/2554",
          "name" : "FEDORA-2007-198",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.rpath.com/pipermail/security-announce/2007-February/000141.html",
          "name" : "[security-announce] 20070206 rPSA-2007-0025-1 postgresql postgresql-server",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33302",
          "name" : "33302",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24028",
          "name" : "24028",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24033",
          "name" : "24033",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24042",
          "name" : "24042",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24050",
          "name" : "24050",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24057",
          "name" : "24057",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24151",
          "name" : "24151",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24315",
          "name" : "24315",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24513",
          "name" : "24513",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24577",
          "name" : "24577",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25220",
          "name" : "25220",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-15.xml",
          "name" : "GLSA-200703-15",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017597",
          "name" : "1017597",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1",
          "name" : "102825",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:037",
          "name" : "MDKSA-2007:037",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_10_sr.html",
          "name" : "SUSE-SR:2007:010",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/support/security",
          "name" : "http://www.postgresql.org/support/security",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0067.html",
          "name" : "RHSA-2007:0067",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0068.html",
          "name" : "RHSA-2007:0068",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459280/100/0/threaded",
          "name" : "20070206 rPSA-2007-0025-1 postgresql postgresql-server",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459448/100/0/threaded",
          "name" : "20070208 rPSA-2007-0025-2 postgresql postgresql-server",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22387",
          "name" : "22387",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0007",
          "name" : "2007-0007",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-417-2",
          "name" : "USN-417-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0478",
          "name" : "ADV-2007-0478",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0774",
          "name" : "ADV-2007-0774",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32191",
          "name" : "postgresql-datatype-information-disclosure(32191)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1025",
          "name" : "https://issues.rpath.com/browse/RPL-1025",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-830",
          "name" : "https://issues.rpath.com/browse/RPL-830",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11353",
          "name" : "oval:org.mitre.oval:def:11353",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/417-1/",
          "name" : "USN-417-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a \"previously made query plan,\" which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content via an \"ALTER COLUMN TYPE\" SQL statement, which can be leveraged to read arbitrary memory from the server."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:1.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:1.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:1.09:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:S/C:C/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0557",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rmake",
            "product" : {
              "product_data" : [ {
                "product_name" : "rmake",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32971",
          "name" : "32971",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1002",
          "name" : "https://issues.rpath.com/browse/RPL-1002",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "rMake before 1.0.4 drops root privileges in a way that retains the original supplemental groups, which might allow attackers to gain privileges via a crafted recipe file, a different vulnerability than CVE-2007-0536."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rmake:rmake:1.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-29T22:28Z",
    "lastModifiedDate" : "2008-11-15T06:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0558",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "inter7",
            "product" : {
              "product_data" : [ {
                "product_name" : "vhostadmin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36627",
          "name" : "36627",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0339",
          "name" : "ADV-2007-0339",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3191",
          "name" : "3191",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the MODULES_DIR parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:inter7:vhostadmin:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T16:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0559",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rp_world",
            "product" : {
              "product_data" : [ {
                "product_name" : "rp_world",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36626",
          "name" : "36626",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0342",
          "name" : "ADV-2007-0342",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3185",
          "name" : "3185",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the sql_language parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rp_world:rp_world:1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T16:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0560",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "asp_edge",
            "product" : {
              "product_data" : [ {
                "product_name" : "asp_edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31619",
          "name" : "31619",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23894",
          "name" : "23894",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458058/100/100/threaded",
          "name" : "20070125 ASP EDGE <= V1.2b (user.asp) Remote SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22212",
          "name" : "22212",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0341",
          "name" : "ADV-2007-0341",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31723",
          "name" : "aspedge-user-sql-injection(31723)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3186",
          "name" : "3186",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in user.asp in ASP EDGE 1.2b and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:asp_edge:asp_edge:1.2b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T16:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0561",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xero_portal",
            "product" : {
              "product_data" : [ {
                "product_name" : "xero_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31634",
          "name" : "31634",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31977",
          "name" : "31977",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31978",
          "name" : "31978",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31979",
          "name" : "31979",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31980",
          "name" : "31980",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31981",
          "name" : "31981",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23952",
          "name" : "23952",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458059/100/0/threaded",
          "name" : "20070125 Xero Portal v1.2 (phpbb_root_path) Remote File Include Vulnerablity",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22227",
          "name" : "22227",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0338",
          "name" : "ADV-2007-0338",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31767",
          "name" : "xero-multiple-scripts-file-include(31767)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3192",
          "name" : "3192",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_linkdb.php, (2) admin_forum_prune.php, (3) admin_extensions.php, (4) admin_board.php, (5) admin_attachments.php, or (6) admin_users.php in admin/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xero_portal:xero_portal:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T16:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0562",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.00.2900.2180",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/43307",
          "name" : "43307",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3190",
          "name" : "3190",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:windows_explorer:6.00.2900.2180:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-30T16:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0563",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.72",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.63",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.67",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.68",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32960",
          "name" : "32960",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32961",
          "name" : "32961",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23896",
          "name" : "23896",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html",
          "name" : "http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017558",
          "name" : "1017558",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22184",
          "name" : "22184",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0330",
          "name" : "ADV-2007-0330",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31750",
          "name" : "symantec-html-xss(31750)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web Security (SWS) before 3.0.1.85 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) error messages and (2) blocked page messages produced by SWS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.0.1.72:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.59:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.63:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.67:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.68:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-30T16:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0564",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.72",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "3.01.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.63",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.67",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.68",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23896",
          "name" : "23896",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html",
          "name" : "http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://securitytracker.com/id?1017558",
          "name" : "1017558",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0330",
          "name" : "ADV-2007-0330",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The license registering interface in Symantec Web Security (SWS) before 3.0.1.85 allows attackers to cause a denial of service (CPU consumption) by submitting a large file."
        }, {
          "lang" : "en",
          "value" : "This vulnerablity is addressed in the following product release:\r\nSymantec, Symantec Web Security, 3.0.1.85"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0.1.72"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.59:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.63:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.67:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:web_security:3.01.68:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T16:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0565",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cgi-rescue",
            "product" : {
              "product_data" : [ {
                "product_name" : "shopping_basket_professional",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.50",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/jp/JVN%2382258242/index.html",
          "name" : "JVN#82258242",
          "refsource" : "JVN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/31622",
          "name" : "31622",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23909",
          "name" : "23909",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22245",
          "name" : "22245",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CGI-Rescue Shopping Basket Professional 7.50 and earlier allows remote attackers to inject arbitrary operating system commands via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cgi-rescue:shopping_basket_professional:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.50"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T16:28Z",
    "lastModifiedDate" : "2008-11-15T06:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0566",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "asp_news",
            "product" : {
              "product_data" : [ {
                "product_name" : "asp_news",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33582",
          "name" : "33582",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458057/100/100/threaded",
          "name" : "20070125 ASP NEWS <= V3 (news_detail.asp) Remote SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22214",
          "name" : "22214",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0340",
          "name" : "ADV-2007-0340",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31719",
          "name" : "aspnews-newsdetail-sql-injection(31719)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3187",
          "name" : "3187",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:asp_news:asp_news:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T16:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0567",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "interactive-scripts.com",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_membership_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33601",
          "name" : "33601",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458226/100/0/threaded",
          "name" : "20070126 PHP Membership Manager Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22263",
          "name" : "22263",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31916",
          "name" : "phpmembership-admin-xss(31916)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:interactive-scripts.com:php_membership_manager:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0568",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "myphpcommander",
            "product" : {
              "product_data" : [ {
                "product_name" : "myphpcommander",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32055",
          "name" : "32055",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23890",
          "name" : "23890",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22257",
          "name" : "22257",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0385",
          "name" : "ADV-2007-0385",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31906",
          "name" : "myphpcommander-package-file-include(31906)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3201",
          "name" : "3201",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the gl_root parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:myphpcommander:myphpcommander:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0569",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "x-dev",
            "product" : {
              "product_data" : [ {
                "product_name" : "xnews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32999",
          "name" : "32999",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23954",
          "name" : "23954",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22284",
          "name" : "22284",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31855",
          "name" : "xnews-xnews-sql-injection(31855)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3216",
          "name" : "3216",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a shownews action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:x-dev:xnews:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0570",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "johannes_gijsbers",
            "product" : {
              "product_data" : [ {
                "product_name" : "ad_fundum_integratable_news_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.02b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36620",
          "name" : "36620",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22259",
          "name" : "22259",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0384",
          "name" : "ADV-2007-0384",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31850",
          "name" : "ains-ainsmain-file-include(31850)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3202",
          "name" : "3202",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News Script (AINS) 0.02b allows remote attackers to execute arbitrary PHP code via a URL in the ains_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:johannes_gijsbers:ad_fundum_integratable_news_script:0.02b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0571",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpmyreports",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpmyreports",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33003",
          "name" : "33003",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23959",
          "name" : "23959",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22290",
          "name" : "22290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0386",
          "name" : "ADV-2007-0386",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31857",
          "name" : "phpmyreports-libhead-file-include(31857)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3212",
          "name" : "3212",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathModule parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpmyreports:phpmyreports:3.0.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0572",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drunken_golem",
            "product" : {
              "product_data" : [ {
                "product_name" : "gaming_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.1_alpha_2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36619",
          "name" : "36619",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0390",
          "name" : "ADV-2007-0390",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31873",
          "name" : "drunkengolem-phpirc-file-include(31873)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3207",
          "name" : "3207",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drunken_golem:gaming_portal:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.5.1_alpha_2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0573",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nsgalphp",
            "product" : {
              "product_data" : [ {
                "product_name" : "nsgalphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.41",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32994",
          "name" : "32994",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23969",
          "name" : "23969",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001257.html",
          "name" : "VIM 20070130 Source VERIFY: nsGalPHP RFI",
          "refsource" : "MLIST",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22277",
          "name" : "22277",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0392",
          "name" : "ADV-2007-0392",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31861",
          "name" : "nsgalphp-config-file-include(31861)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3205",
          "name" : "3205",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racineTBS parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nsgalphp:nsgalphp:0.41:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0574",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spoonlabs",
            "product" : {
              "product_data" : [ {
                "product_name" : "vivvo_article_management_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.40",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36631",
          "name" : "36631",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22282",
          "name" : "22282",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spoonlabs:vivvo_article_management_cms:3.40:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2008-11-13T06:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0575",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "stefan_holmberg",
            "product" : {
              "product_data" : [ {
                "product_name" : "admentor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2606",
          "name" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2606",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2207",
          "name" : "2207",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458303/100/0/threaded",
          "name" : "20070127 AdMentor (banners) admin SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460632/100/100/threaded",
          "name" : "20070220 AdMentor Script Remote SQL injection Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22281",
          "name" : "22281",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31908",
          "name" : "admentor-adminlogin-sql-injection(31908)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in the administrative login page (admin/login.asp) in ASPCode.net AdMentor allow remote attackers to execute arbitrary SQL commands via the (1) Userid and (2) Password fields."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_holmberg:admentor:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0576",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xt-stats",
            "product" : {
              "product_data" : [ {
                "product_name" : "xt-stats",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.b3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32980",
          "name" : "32980",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/bugtraq/2007/Jan/0643.html",
          "name" : "20070127 Xt-Stats v.2.4.0.b3 - Remote File Include Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23967",
          "name" : "23967",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22276",
          "name" : "22276",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0387",
          "name" : "ADV-2007-0387",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xt-scripts.com/",
          "name" : "http://www.xt-scripts.com/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31871",
          "name" : "xtstats-xtcounter-file-include(31871)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3209",
          "name" : "3209",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a URL in the server_base_dir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xt-stats:xt-stats:2.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xt-stats:xt-stats:2.4.0.b3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0577",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "acgvclick",
            "product" : {
              "product_data" : [ {
                "product_name" : "acgvclick",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23970",
          "name" : "23970",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22278",
          "name" : "22278",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0391",
          "name" : "ADV-2007-0391",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31859",
          "name" : "acgvclick-function-file-include(31859)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3206",
          "name" : "3206",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:acgvclick:acgvclick:0.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0578",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mpg123",
            "product" : {
              "product_data" : [ {
                "product_name" : "mpg123",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.59m",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.59n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.59o",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.59p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.59q",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.59r",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.59s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.63",
                    "version_affected" : "="
                  }, {
                    "version_value" : "pre0.59s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "pre0.59s_r11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/40128",
          "name" : "40128",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=135704&release_id=478747",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=135704&release_id=478747",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:032",
          "name" : "MDKSA-2007:032",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mpg123.de/cgi-bin/news.cgi",
          "name" : "http://www.mpg123.de/cgi-bin/news.cgi",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22274",
          "name" : "22274",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0366",
          "name" : "ADV-2007-0366",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mpg123:mpg123:0.59m:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mpg123:mpg123:0.59n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mpg123:mpg123:0.59o:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mpg123:mpg123:0.59p:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mpg123:mpg123:0.59q:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mpg123:mpg123:0.59r:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mpg123:mpg123:0.59s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mpg123:mpg123:0.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mpg123:mpg123:0.63:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mpg123:mpg123:pre0.59s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mpg123:mpg123:pre0.59s_r11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0579",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "horde",
            "product" : {
              "product_data" : [ {
                "product_name" : "groupware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.horde.org/archives/announce/2007/000308.html",
          "name" : "[horde-announce] 20070114 Horde Groupware 1.0 (final)",
          "refsource" : "MLIST",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.horde.org/archives/announce/2007/000309.html",
          "name" : "[horde-announce] 20070114 Horde Groupware Webmail Edition 1.0 (final)",
          "refsource" : "MLIST",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33083",
          "name" : "33083",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22273",
          "name" : "22273",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0368",
          "name" : "ADV-2007-0368",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31849",
          "name" : "horde-calendar-file-include(31849)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition before 1.0, and Groupware before 1.0, allows remote attackers to include certain files via unspecified vectors.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:horde:groupware:1.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:horde:groupware:1.0_rc3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0580",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "javier_suarez_sanz",
            "product" : {
              "product_data" : [ {
                "product_name" : "foro_domus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33004",
          "name" : "33004",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23949",
          "name" : "23949",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22285",
          "name" : "22285",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0396",
          "name" : "ADV-2007-0396",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31853",
          "name" : "forodomus-menu-file-include(31853)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3215",
          "name" : "3215",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP code via a URL in the sesion_idioma parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:javier_suarez_sanz:foro_domus:2.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0581",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eclipsebb",
            "product" : {
              "product_data" : [ {
                "product_name" : "eclipsebb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.0_lite",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35416",
          "name" : "35416",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/466172/100/0/threaded",
          "name" : "20070418 EclipseBB Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22283",
          "name" : "22283",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0397",
          "name" : "ADV-2007-0397",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31852",
          "name" : "eclipsebb-functions-file-include(31852)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3214",
          "name" : "3214",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eclipsebb:eclipsebb:0.5.0_lite:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0582",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "chernobile",
            "product" : {
              "product_data" : [ {
                "product_name" : "chernobile",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36618",
          "name" : "36618",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22280",
          "name" : "22280",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31939",
          "name" : "chernobile-default-sql-injection(31939)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3210",
          "name" : "3210",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands via the User (username) field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:chernobile:chernobile:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0583",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "http_commander",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_commander",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32985",
          "name" : "32985",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32986",
          "name" : "32986",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23964",
          "name" : "23964",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22298",
          "name" : "22298",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31877",
          "name" : "httpcommander-multiple-xss(31877)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in HTTP Commander 6.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) LogoffMessage parameter to logofflast.aspx or the (2) txtUsername parameter to Default.aspx. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:http_commander:http_commander:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0584",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "g-neric",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_generic_library_and_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33606",
          "name" : "33606",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/36632",
          "name" : "36632",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458556/100/0/threaded",
          "name" : "20070129 PhP Generic library & framework (include_path) Remote File Include Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22287",
          "name" : "22287",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0394",
          "name" : "ADV-2007-0394",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31895",
          "name" : "phpgeneric-membremanager-file-include(31895)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3217",
          "name" : "3217",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in membres/membreManager.php in PhP Generic Library & Framework for comm (g-neric) allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:g-neric:php_generic_library_and_framework:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0585",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webfwlog",
            "product" : {
              "product_data" : [ {
                "product_name" : "webfwlog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.92",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33015",
          "name" : "33015",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23968",
          "name" : "23968",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://webfwlog.cvs.sourceforge.net/*checkout*/webfwlog/webfwlog/ChangeLog",
          "name" : "http://webfwlog.cvs.sourceforge.net/*checkout*/webfwlog/webfwlog/ChangeLog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22291",
          "name" : "22291",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0399",
          "name" : "ADV-2007-0399",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31881",
          "name" : "webfwlog-debug-file-include(31881)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3222",
          "name" : "3222",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conffile parameter.  NOTE: some of these details are obtained from third party information.  It is likely that this issue can be exploited to conduct directory traversal attacks."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that \"register_globals\" is enabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webfwlog:webfwlog:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.92"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T17:28Z",
    "lastModifiedDate" : "2018-08-13T21:47Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0588",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security-protocols.com/sp-x43-advisory.php",
          "name" : "http://security-protocols.com/sp-x43-advisory.php",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/396820",
          "name" : "VU#396820",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/33365",
          "name" : "33365",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22228",
          "name" : "22228",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017760",
          "name" : "1017760",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT file that triggers memory corruption in the _GetSrcBits32ARGB function. NOTE: this issue might overlap CVE-2007-0462."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2013-08-15T05:21Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0589",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "forum_livre",
            "product" : {
              "product_data" : [ {
                "product_name" : "forum_livre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36644",
          "name" : "36644",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3197",
          "name" : "3197",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to info_user.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:forum_livre:forum_livre:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0590",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "forum_livre",
            "product" : {
              "product_data" : [ {
                "product_name" : "forum_livre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36645",
          "name" : "36645",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3197",
          "name" : "3197",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web script or HTML via the palavra parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:forum_livre:forum_livre:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0591",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vu_le_an",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_path",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31636",
          "name" : "31636",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23918",
          "name" : "23918",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22241",
          "name" : "22241",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0352",
          "name" : "ADV-2007-0352",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3198",
          "name" : "3198",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vu_le_an:virtual_path:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0592",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "indexcor",
            "product" : {
              "product_data" : [ {
                "product_name" : "ezdatabase",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36954",
          "name" : "36954",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/36955",
          "name" : "36955",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2196",
          "name" : "2196",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458062/100/0/threaded",
          "name" : "20070125 EzDatabase Multiple Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22235",
          "name" : "22235",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31768",
          "name" : "ezdatabase-adminpanel-xss(31768)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in EzDatabase 2.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to admin/login.php and the Admin Panel Database."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:indexcor:ezdatabase:2.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0593",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "siteman",
            "product" : {
              "product_data" : [ {
                "product_name" : "siteman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31662",
          "name" : "31662",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23925",
          "name" : "23925",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2205",
          "name" : "2205",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458092/100/0/threaded",
          "name" : "20070125 [x0n3-h4ck] Siteman 1.1.11 Remote Md5 Hash Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/31440",
          "name" : "31440",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31780",
          "name" : "siteman-members-information-disclosure(31780)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/45485",
          "name" : "siteman-members-info-disclosure(45485)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Siteman 1.1.11 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing password hashes via a direct request for data/members.txt."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:siteman:siteman:1.1.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0594",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "siteman",
            "product" : {
              "product_data" : [ {
                "product_name" : "siteman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.x2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33590",
          "name" : "33590",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2206",
          "name" : "2206",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458081/100/0/threaded",
          "name" : "20070125 [x0n3-h4ck] Siteman 2.0.x2 Remote Md5 Hash Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Siteman 2.0.x2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing password hashes via a direct request for db/siteman/users.MYD."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:siteman:siteman:2.0.x2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0595",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "designmind",
            "product" : {
              "product_data" : [ {
                "product_name" : "high5_review_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32974",
          "name" : "32974",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23905",
          "name" : "23905",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458122/100/0/threaded",
          "name" : "20070125 high5 Review script Security Risk",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0363",
          "name" : "ADV-2007-0363",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31797",
          "name" : "high5review-search-xss(31797)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search in High 5 Review Site allows remote attackers to inject arbitrary web script or HTML via the q parameter (aka the search box)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:designmind:high5_review_script:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0596",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aztek_forum",
            "product" : {
              "product_data" : [ {
                "product_name" : "aztek_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://acid-root.new.fr/poc/21070125.txt",
          "name" : "http://acid-root.new.fr/poc/21070125.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33593",
          "name" : "33593",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458076/100/0/threaded",
          "name" : "20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458123/100/0/threaded",
          "name" : "20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in index/main.php in Aztek Forum 4.00 allows remote authenticated administrators to execute arbitrary PHP code via a URL in the PF[top_url] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aztek_forum:aztek_forum:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0597",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aztek_forum",
            "product" : {
              "product_data" : [ {
                "product_name" : "aztek_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://acid-root.new.fr/poc/21070125.txt",
          "name" : "http://acid-root.new.fr/poc/21070125.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33594",
          "name" : "33594",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458076/100/0/threaded",
          "name" : "20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458123/100/0/threaded",
          "name" : "20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Aztek Forum 4.00 allows remote attackers to obtain sensitive information via a direct request to forum.php with the fid=XD query string, which reveals the path in an error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aztek_forum:aztek_forum:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0598",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aztek_forum",
            "product" : {
              "product_data" : [ {
                "product_name" : "aztek_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://acid-root.new.fr/poc/21070125.txt",
          "name" : "http://acid-root.new.fr/poc/21070125.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33595",
          "name" : "33595",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458076/100/0/threaded",
          "name" : "20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458123/100/0/threaded",
          "name" : "20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in forum/load.php in Aztek Forum 4.00 allows remote attackers to execute arbitrary SQL commands via the fid cookie to forum.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aztek_forum:aztek_forum:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0599",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aztek_forum",
            "product" : {
              "product_data" : [ {
                "product_name" : "aztek_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://acid-root.new.fr/poc/21070125.txt",
          "name" : "http://acid-root.new.fr/poc/21070125.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33596",
          "name" : "33596",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458076/100/0/threaded",
          "name" : "20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458123/100/0/threaded",
          "name" : "20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Variable overwrite vulnerability in common/config.php in Aztek Forum 4.00 allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as copying arbitrary files using index/common_actions.php, via vectors associated with extract operations on the (1) POST, (2) GET, (3) COOKIE, and (4) SERVER superglobal arrays."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aztek_forum:aztek_forum:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0600",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "makit",
            "product" : {
              "product_data" : [ {
                "product_name" : "newsposter_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "martyn_kilbryde",
            "product" : {
              "product_data" : [ {
                "product_name" : "newsposter_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31640",
          "name" : "31640",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/36633",
          "name" : "36633",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23930",
          "name" : "23930",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2208",
          "name" : "2208",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458063/100/0/threaded",
          "name" : "20070125 makit news/blog poster <=v3(news_page.asp) Remote SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22230",
          "name" : "22230",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0354",
          "name" : "ADV-2007-0354",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31747",
          "name" : "newsposter-newspage-sql-injection(31747)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3194",
          "name" : "3194",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:makit:newsposter_script:0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:martyn_kilbryde:newsposter_script:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0601",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aztek_forum",
            "product" : {
              "product_data" : [ {
                "product_name" : "aztek_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://acid-root.new.fr/poc/21070125.txt",
          "name" : "http://acid-root.new.fr/poc/21070125.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33597",
          "name" : "33597",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458076/100/0/threaded",
          "name" : "20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458123/100/0/threaded",
          "name" : "20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "common/safety.php in Aztek Forum 4.00 allows remote attackers to enter certain data containing %22 sequences (URL encoded double quotes) and other potentially dangerous manipulations by sending a cookie, which bypasses the blacklist matching against the GET and PUT superglobal arrays."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aztek_forum:aztek_forum:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0602",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trend_micro",
            "product" : {
              "product_data" : [ {
                "product_name" : "viruswall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.81",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034124&id=EN-1034124",
          "name" : "http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034124&id=EN-1034124",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://osvdb.org/33043",
          "name" : "33043",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2204",
          "name" : "2204",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017562",
          "name" : "1017562",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.devtarget.org/tmvwall381v3_exp.c",
          "name" : "http://www.devtarget.org/tmvwall381v3_exp.c",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.devtarget.org/trendmicro-advisory-01-2007.txt",
          "name" : "http://www.devtarget.org/trendmicro-advisory-01-2007.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458111/100/0/threaded",
          "name" : "20070125 Buffer overflow in VSAPI library of Trend Micro VirusWall 3.81 for Linux",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0367",
          "name" : "ADV-2007-0367",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in libvsapi.so in the VSAPI library in Trend Micro VirusWall 3.81 for Linux, as used by IScan.BASE/vscan, allows local users to gain privileges via a long command line argument, a different vulnerability than CVE-2005-0533."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:viruswall:3.81:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0603",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pgp",
            "product" : {
              "product_data" : [ {
                "product_name" : "corporate_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/vulnwatch/2007-q1/0025.html",
          "name" : "20070125 Medium Risk Vulnerability in PGP Desktop",
          "refsource" : "VULNWATCH",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32969",
          "name" : "32969",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32970",
          "name" : "32970",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23938",
          "name" : "23938",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2203",
          "name" : "2203",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017563",
          "name" : "1017563",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/102465",
          "name" : "VU#102465",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-pgp-desktop/",
          "name" : "http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-pgp-desktop/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458137/100/0/threaded",
          "name" : "20070125 Medium Risk Vulnerability in PGP Desktop",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22247",
          "name" : "22247",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0356",
          "name" : "ADV-2007-0356",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PGP Desktop before 9.5.1 does not validate data objects received over the (1) \\pipe\\pgpserv named pipe for PGPServ.exe or the (2) \\pipe\\pgpsdkserv named pipe for PGPsdkServ.exe, which allows remote authenticated users to gain privileges by sending a data object representing an absolute pointer, which causes code execution at the corresponding address."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pgp:corporate_desktop:9.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0604",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "six_apart_ltd",
            "product" : {
              "product_data" : [ {
                "product_name" : "movable_type",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.33",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32987",
          "name" : "32987",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.sixapart.com/movabletype/beta/distros/MT-3.34-beta-Release-Notes.html",
          "name" : "http://www.sixapart.com/movabletype/beta/distros/MT-3.34-beta-Release-Notes.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Movable Type (MT) before 3.34 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the MTCommentPreviewIsStatic tag, which can open the \"comment entry screen,\" a different vulnerability than CVE-2007-0231."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:six_apart_ltd:movable_type:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.33"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-30T18:28Z",
    "lastModifiedDate" : "2008-11-15T06:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0605",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "advanced_guestbook",
            "product" : {
              "product_data" : [ {
                "product_name" : "advanced_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/25153",
          "name" : "25153",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2663",
          "name" : "2663",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.netvigilance.com/advisory0012",
          "name" : "http://www.netvigilance.com/advisory0012",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/33877",
          "name" : "33877",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/467937/100/0/threaded",
          "name" : "20070507 Advanced Guestbook version 2.4.2 Multiple XSS Attack Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23873",
          "name" : "23873",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1726",
          "name" : "ADV-2007-1726",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34156",
          "name" : "advanced-picture-index-xss(34156)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in picture.php in Advanced Guestbook 2.4.2 allows remote attackers to inject arbitrary web script or HTML via the picture parameter."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that \"register_globals\" is enabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:advanced_guestbook:advanced_guestbook:2.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-09T17:19Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0606",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "w-agora",
            "product" : {
              "product_data" : [ {
                "product_name" : "w-agora",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2461",
          "name" : "2461",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.netvigilance.com/advisory0014",
          "name" : "http://www.netvigilance.com/advisory0014",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/31668",
          "name" : "31668",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/31669",
          "name" : "31669",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/463213/100/0/threaded",
          "name" : "20070319 w-agora version 4.2.1 Multiple Path Disclosure Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33076",
          "name" : "wagora-deleteforumindex-path-disclosure(33076)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "w-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php, which expects a string, and (2) certain parameters to delete_forum.php, which displays the path name in the resulting error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:w-agora:w-agora:4.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-21T19:19Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0607",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "w-agora",
            "product" : {
              "product_data" : [ {
                "product_name" : "w-agora",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053054.html",
          "name" : "20070319 w-agora version 4.2.1 Information Disclosure Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2465",
          "name" : "2465",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.netvigilance.com/advisory0015",
          "name" : "http://www.netvigilance.com/advisory0015",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/31670",
          "name" : "31670",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/463215/100/0/threaded",
          "name" : "20070319 w-agora version 4.2.1 Information Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33073",
          "name" : "wagora-globals-information-disclosure(33073)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "W-Agora (Web-Agora) 4.2.1, when register_globals is enabled, stores globals.inc under the web document root with insufficient access control, which allows remote attackers to obtain application path information via a direct request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:w-agora:w-agora:4.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-20T20:19Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0608",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "advanced_guestbook",
            "product" : {
              "product_data" : [ {
                "product_name" : "advanced_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34362",
          "name" : "34362",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25153",
          "name" : "25153",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2661",
          "name" : "2661",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.netvigilance.com/advisory0011",
          "name" : "http://www.netvigilance.com/advisory0011",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/33876",
          "name" : "33876",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33878",
          "name" : "33878",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33879",
          "name" : "33879",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/467940/100/0/threaded",
          "name" : "20070507 Advanced Guestbook version 2.4.2 Multiple Error Information Leak Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1726",
          "name" : "ADV-2007-1726",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34161",
          "name" : "advanced-multiple-script-info-disclosure(34161)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Advanced Guestbook 2.4.2 allows remote attackers to obtain sensitive information via an invalid (1) GB_TBL parameter to (a) lang/codes-english.php or (b) image.php, which reveal the database name; (2) an invalid GB_DB parameter to index.php, coupled with a ../index lang cookie, which reveals the installation path; or (3) a direct request to index.php with no parameters or cookies, which reveals the installation path."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that \"register_globals\" is enabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:advanced_guestbook:advanced_guestbook:2.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-09T17:19Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0609",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "advanced_guestbook",
            "product" : {
              "product_data" : [ {
                "product_name" : "advanced_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/25153",
          "name" : "25153",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2662",
          "name" : "2662",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.netvigilance.com/advisory0012",
          "name" : "http://www.netvigilance.com/advisory0012",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.netvigilance.com/advisory0013",
          "name" : "http://www.netvigilance.com/advisory0013",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/467937/100/0/threaded",
          "name" : "20070507 Advanced Guestbook version 2.4.2 Multiple XSS Attack Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/467941/100/0/threaded",
          "name" : "20070507 Advanced Guestbook version 2.4.2 Directory Traversal Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23876",
          "name" : "23876",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1726",
          "name" : "ADV-2007-1726",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34152",
          "name" : "advanced-index-directory-traversal(34152)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local files or read arbitrary local templates, via a .. (dot dot) in a lang cookie, followed by a filename without its .php extension, as demonstrated via a request to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:advanced_guestbook:advanced_guestbook:2.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-09T17:19Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0610",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cmsmadesimple",
            "product" : {
              "product_data" : [ {
                "product_name" : "cms_made_simple",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32976",
          "name" : "32976",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23951",
          "name" : "23951",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22250",
          "name" : "22250",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31841",
          "name" : "cmsimple-sender-xss(31841)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the mailform feature in CMSimple 2.7 fix1 allows remote attackers to inject arbitrary web script or HTML via the sender parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cmsmadesimple:cms_made_simple:2.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0611",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "free_lan_intra_internet_portal",
            "product" : {
              "product_data" : [ {
                "product_name" : "free_lan_intra_internet_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0_rc1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36682",
          "name" : "36682",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/36683",
          "name" : "36683",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=480714&group_id=98260",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=480714&group_id=98260",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0360",
          "name" : "ADV-2007-0360",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) inc.page.php and (2) inc.text.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0_rc1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T01:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0612",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0_ta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0547.html",
          "name" : "20070128 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052057.html",
          "name" : "20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32628",
          "name" : "32628",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2199",
          "name" : "2199",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html",
          "name" : "http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458443/100/0/threaded",
          "name" : "20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22288",
          "name" : "22288",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31867",
          "name" : "ie-activex-bgcolor-dos(31867)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.0.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.0.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.0_ta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:vista:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:beta2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0613",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "ichat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "instant_message_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "428",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mdnsresponder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://projects.info-pull.com/moab/MOAB-29-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-29-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/32698",
          "name" : "32698",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32699",
          "name" : "32699",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22304",
          "name" : "22304",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of service (disrupted communication) via a flood of duplicate _presence._tcp mDNS queries."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:ichat:3.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:instant_message_framework:428:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:mdnsresponder:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T11:28Z",
    "lastModifiedDate" : "2008-09-05T21:18Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0614",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "ichat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.6",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "instant_message_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "428",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305102",
          "name" : "http://docs.info.apple.com/article.html?artnum=305102",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html",
          "name" : "APPLE-SA-2007-02-15",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://projects.info-pull.com/moab/MOAB-29-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-29-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/23945",
          "name" : "23945",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24198",
          "name" : "24198",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32713",
          "name" : "32713",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22304",
          "name" : "22304",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017661",
          "name" : "1017661",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:ichat:3.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:instant_message_framework:428:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T11:28Z",
    "lastModifiedDate" : "2008-09-05T21:18Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0615",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hitachi",
            "product" : {
              "product_data" : [ {
                "product_name" : "hibun_advanced_edition_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r-1v13-06w001f1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jpi_hibun_advanced_edition_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r_1543h_11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32963",
          "name" : "32963",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23854",
          "name" : "23854",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-019_e/01-e.html",
          "name" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-019_e/01-e.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22237",
          "name" : "22237",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0324",
          "name" : "ADV-2007-0324",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31733",
          "name" : "hitachi-jp1-hibun-request-dos(31733)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Hitachi JP1/HIBUN Advanced Edition Management Server and Log Server before 20070124 allows remote attackers to cause a denial of service (application stop) via unexpected data."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hibun_advanced_edition_server:r-1v13-06w001f1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_hibun_advanced_edition_server:r_1543h_11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T11:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0616",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zenphoto",
            "product" : {
              "product_data" : [ {
                "product_name" : "zenphoto",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33072",
          "name" : "33072",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24026",
          "name" : "24026",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22368",
          "name" : "22368",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0470",
          "name" : "ADV-2007-0470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zenphoto.org/support/topic.php?id=1146&replies=3",
          "name" : "http://www.zenphoto.org/support/topic.php?id=1146&replies=3",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.zenphoto.org/support/topic.php?id=1148",
          "name" : "http://www.zenphoto.org/support/topic.php?id=1148",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32102",
          "name" : "zenphoto-template-directory-traversal(32102)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in zen/template-functions.php in zenphoto 1.0.4 up to 1.0.6 allows remote attackers to list arbitrary directories via \"..\" sequences in the album parameter to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zenphoto:zenphoto:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zenphoto:zenphoto:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zenphoto:zenphoto:1.0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T11:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0617",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "earthlink",
            "product" : {
              "product_data" : [ {
                "product_name" : "total_access",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052021.html",
          "name" : "20070125 Earthlink TotalAccess ActiveX Unsafe Methods Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2210",
          "name" : "2210",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22238",
          "name" : "22238",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31827",
          "name" : "earthlink-spamblocker-security-bypass(31827)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The SpamBlocker.dll ActiveX control in Earthlink TotalAccess is marked \"safe for scripting,\" which allows remote attackers to add arbitrary e-mail addresses and domains to the spam blocker whitelist via the (1) AddSenderToWhitelist and (2) AddDomainToWhitelist functions."
        }, {
          "lang" : "en",
          "value" : "Medium complexity because phishing attack"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:earthlink:total_access:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-31T11:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0618",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://aix.software.ibm.com/aix/efixes/security/README",
          "name" : "ftp://aix.software.ibm.com/aix/efixes/security/README",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23957",
          "name" : "23957",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22262",
          "name" : "22262",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0382",
          "name" : "ADV-2007-0382",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/search.wss?rs=0&q=IY93084&apar=only",
          "name" : "IY93084",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31875",
          "name" : "aix-mailservices-rlogin-security-bypass(31875)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an \"authentication vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T11:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0619",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "chmlib",
            "product" : {
              "product_data" : [ {
                "product_name" : "chmlib",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.38",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=468",
          "name" : "20070126 Multiple Vendor libchm Page Block Length Memory Corruption Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://morte.jedrea.com/~jedwin/projects/chmlib/",
          "name" : "http://morte.jedrea.com/~jedwin/projects/chmlib/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/23975",
          "name" : "23975",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24335",
          "name" : "24335",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200702-12.xml",
          "name" : "GLSA-200702-12",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017565",
          "name" : "1017565",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_3_sr.html",
          "name" : "SUSE-SR:2007:003",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22258",
          "name" : "22258",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0361",
          "name" : "ADV-2007-0361",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "chmlib before 0.39 allows user-assisted remote attackers to execute arbitrary code via a crafted page block length in a CHM file, which triggers memory corruption."
        }, {
          "lang" : "en",
          "value" : "Update to version 0.39."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:chmlib:chmlib:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.38"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-31T11:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0620",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vlad_leont",
            "product" : {
              "product_data" : [ {
                "product_name" : "fd_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33001",
          "name" : "33001",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23947",
          "name" : "23947",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2197",
          "name" : "2197",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458231/100/0/threaded",
          "name" : "20070126 FdScript <= v1.3.2 Remote File Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22265",
          "name" : "22265",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0383",
          "name" : "ADV-2007-0383",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31915",
          "name" : "fdscript-download-file-disclosure(31915)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vlad_leont:fd_script:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vlad_leont:fd_script:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vlad_leont:fd_script:1.3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0621",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-6456.  Reason: This candidate is a duplicate of CVE-2006-6456.  It was assigned for a targeted zero-day attack, but further analysis revealed it was for an older issue.  Notes: All CVE users should reference CVE-2006-6456 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2007-01-31T17:28Z",
    "lastModifiedDate" : "2008-09-11T00:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0622",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32968",
          "name" : "32968",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23934",
          "name" : "23934",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in MyBB (aka MyBulletinBoard) 1.2.2 allows remote attackers to send messages to arbitrary users.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:1.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T18:28Z",
    "lastModifiedDate" : "2008-11-15T06:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0623",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "maxdev",
            "product" : {
              "product_data" : [ {
                "product_name" : "mdpro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.76",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33011",
          "name" : "33011",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33612",
          "name" : "33612",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23948",
          "name" : "23948",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2198",
          "name" : "2198",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458438/100/0/threaded",
          "name" : "20070129 MDPro 1.0.76 - Multiple Remote Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22293",
          "name" : "22293",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0412",
          "name" : "ADV-2007-0412",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31897",
          "name" : "mdpro-startrow-sql-injection(31897)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maxdev:mdpro:1.0.76:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0624",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "maxdev",
            "product" : {
              "product_data" : [ {
                "product_name" : "mdpro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.76",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33613",
          "name" : "33613",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2198",
          "name" : "2198",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458438/100/0/threaded",
          "name" : "20070129 MDPro 1.0.76 - Multiple Remote Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31898",
          "name" : "mdpro-user-path-disclosure(31898)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values, in the uname parameter in a userinfo operation."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maxdev:mdpro:1.0.76:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0625",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nomachine",
            "product" : {
              "product_data" : [ {
                "product_name" : "nx_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.0_17",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33009",
          "name" : "33009",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23993",
          "name" : "23993",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.nomachine.com/news_read.php?idnews=190",
          "name" : "http://www.nomachine.com/news_read.php?idnews=190",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.nomachine.com/tr/view.php?id=TR01E01622",
          "name" : "http://www.nomachine.com/tr/view.php?id=TR01E01622",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22308",
          "name" : "22308",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0413",
          "name" : "ADV-2007-0413",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31941",
          "name" : "nxserver-nxconfigure-dos(31941)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "nxconfigure.sh in NoMachine NX Server before 2.1.0-18 does not validate the invoking user, which allows local users to modify server configuration keys in /usr/NX/etc/server.cfg, resulting in an unspecified denial of service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nomachine:nx_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1.0_17"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0626",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "drupal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "vbdrupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "vbdrupal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2007-01/0670.html",
          "name" : "20070129 [DRUPAL-SA-2007-005] Drupal 4.7.6 / 5.1 fixes arbitrary code execution issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://drupal.org/node/113935",
          "name" : "http://drupal.org/node/113935",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32136",
          "name" : "32136",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/23960",
          "name" : "23960",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23990",
          "name" : "23990",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22306",
          "name" : "22306",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vbdrupal.org/forum/showthread.php?t=786",
          "name" : "http://www.vbdrupal.org/forum/showthread.php?t=786",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0406",
          "name" : "ADV-2007-0406",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0415",
          "name" : "ADV-2007-0415",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31940",
          "name" : "drupal-commentformaddpreview-code-execution(31940)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with \"post comments\" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by \"normal form validation routines.\""
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires \"post comments\" privileges and access to multiple input filters (not the default)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
          "versionStartExcluding" : "4.0.0",
          "versionEndExcluding" : "4.7.6"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.0",
          "versionEndExcluding" : "5.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vbdrupal:vbdrupal:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T18:28Z",
    "lastModifiedDate" : "2018-10-19T17:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0627",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "michael_still",
            "product" : {
              "product_data" : [ {
                "product_name" : "gtalkbot",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://freshmeat.net/projects/gtalkbot/?branch_id=67830&release_id=245004",
          "name" : "http://freshmeat.net/projects/gtalkbot/?branch_id=67830&release_id=245004",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33071",
          "name" : "33071",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23942",
          "name" : "23942",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22322",
          "name" : "22322",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.stillhq.com/gtalkbot/",
          "name" : "http://www.stillhq.com/gtalkbot/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.stillhq.com/gtalkbot/000003.html",
          "name" : "http://www.stillhq.com/gtalkbot/000003.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0408",
          "name" : "ADV-2007-0408",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31923",
          "name" : "gtalkbot-ps-information-disclosure(31923)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Michael Still gtalkbot before 1.2 places username and password arguments on the command line, which allows local users to obtain sensitive information by listing the process."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michael_still:gtalkbot:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0628",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "java_system_access_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33010",
          "name" : "33010",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23979",
          "name" : "23979",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017570",
          "name" : "1017570",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102621-1",
          "name" : "102621",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22302",
          "name" : "22302",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0411",
          "name" : "ADV-2007-0411",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31936",
          "name" : "java-access-server-unspecified-xss(31936)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2005Q4 (7.0) before 20070129 allow remote attackers to inject arbitrary web script or HTML via the (1) goto or (2) gx-charset parameter. NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_access_manager:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_access_manager:6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_access_manager:6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_access_manager:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-31T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0629",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "plain_black",
            "product" : {
              "product_data" : [ {
                "product_name" : "webgui",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32992",
          "name" : "32992",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23981",
          "name" : "23981",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=51417&release_id=481584",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=51417&release_id=481584",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.plainblack.com/getwebgui/advisories/security-defect-discovered-in-7.x-versions",
          "name" : "http://www.plainblack.com/getwebgui/advisories/security-defect-discovered-in-7.x-versions",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22294",
          "name" : "22294",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31905",
          "name" : "webgui-wwwpurgelist-security-bypass(31905)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The www_purgeList method in Plain Black WebGUI before 7.3.8 does not properly check user permissions, which allows attackers to delete unauthorized assets.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:7.3.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0630",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "x-dev",
            "product" : {
              "product_data" : [ {
                "product_name" : "xnews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33000",
          "name" : "33000",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0395",
          "name" : "ADV-2007-0395",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in the generate_csv function in classes/class.news.php in X-dev xNews 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) from, and (3) q parameters, different vectors than CVE-2007-0569.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:x-dev:xnews:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T18:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0631",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eclectic_designs",
            "product" : {
              "product_data" : [ {
                "product_name" : "cascadianfaq",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23965",
          "name" : "23965",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/31675",
          "name" : "31675",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22314",
          "name" : "22314",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0424",
          "name" : "ADV-2007-0424",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31968",
          "name" : "cascadianfaq-index-sql-injection(31968)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3227",
          "name" : "3227",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eclectic_designs:cascadianfaq:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0632",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "asp_edge",
            "product" : {
              "product_data" : [ {
                "product_name" : "asp_edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3a",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36634",
          "name" : "36634",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0341",
          "name" : "ADV-2007-0341",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in artreplydelete.asp in ASP EDGE 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via a username cookie, a different vector than CVE-2007-0560."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:asp_edge:asp_edge:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3a"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T18:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0633",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "t-systems_solutions_for_research_gmbh",
            "product" : {
              "product_data" : [ {
                "product_name" : "mynews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33019",
          "name" : "33019",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23973",
          "name" : "23973",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22313",
          "name" : "22313",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0423",
          "name" : "ADV-2007-0423",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31971",
          "name" : "mynews-themefunc-file-include(31971)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3228",
          "name" : "3228",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:t-systems_solutions_for_research_gmbh:mynews:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.2.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0634",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31878",
          "name" : "31878",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23982",
          "name" : "23982",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017574",
          "name" : "1017574",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102697-1",
          "name" : "102697",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/967236",
          "name" : "VU#967236",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22323",
          "name" : "22323",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0420",
          "name" : "ADV-2007-0420",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32010",
          "name" : "solaris-icmp-dos(32010)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1249",
          "name" : "oval:org.mitre.oval:def:1249",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T21:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0635",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "encapscms",
            "product" : {
              "product_data" : [ {
                "product_name" : "encapscms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33034",
          "name" : "33034",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33035",
          "name" : "33035",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33036",
          "name" : "33036",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23987",
          "name" : "23987",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2200",
          "name" : "2200",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458582/100/0/threaded",
          "name" : "20070130 EncapsCMS 0.3.6 (common_foot.php) Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22319",
          "name" : "22319",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0430",
          "name" : "ADV-2007-0430",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31978",
          "name" : "encapsms-config-file-include(31978)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config[path] parameter to (a) common_foot.php or (b) blogs.php, or (2) the config[theme] parameter to (c) admin/gallery_head.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:encapscms:encapscms:0.3.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0636",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "inotify",
            "product" : {
              "product_data" : [ {
                "product_name" : "incron",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://inotify.aiken.cz/?section=incron&page=changelog",
          "name" : "http://inotify.aiken.cz/?section=incron&page=changelog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/38132",
          "name" : "38132",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22305",
          "name" : "22305",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0405",
          "name" : "ADV-2007-0405",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in inotify before 0.3.5 has unknown impact and attack vectors, related to \"access rights to watched files.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:inotify:incron:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:inotify:incron:0.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:inotify:incron:0.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:inotify:incron:0.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:inotify:incron:0.3.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T21:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0637",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "galeria_zdjec",
            "product" : {
              "product_data" : [ {
                "product_name" : "galeria_zdjec",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33033",
          "name" : "33033",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23956",
          "name" : "23956",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22324",
          "name" : "22324",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0425",
          "name" : "ADV-2007-0425",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31967",
          "name" : "galeria-zdnumer-file-include(31967)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3225",
          "name" : "3225",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:galeria_zdjec:galeria_zdjec:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T21:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0638",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vlad_alexa_mancini",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpfootball",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33070",
          "name" : "33070",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23962",
          "name" : "23962",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22312",
          "name" : "22312",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0429",
          "name" : "ADV-2007-0429",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31976",
          "name" : "phpfootball-show-information-disclosure(31976)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3226",
          "name" : "3226",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vlad_alexa_mancini:phpfootball:1.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T21:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0639",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "guppy",
            "product" : {
              "product_data" : [ {
                "product_name" : "guppy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.16",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33016",
          "name" : "33016",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://retrogod.altervista.org/guppy_4516_cmd.html",
          "name" : "http://retrogod.altervista.org/guppy_4516_cmd.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/23914",
          "name" : "23914",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017569",
          "name" : "1017569",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0421",
          "name" : "ADV-2007-0421",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31882",
          "name" : "guppy-error-code-execution(31882)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3221",
          "name" : "3221",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the msg array with an error number in the first dimension and 0 in the second dimension, as demonstrated by msg[999][0]."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:guppy:guppy:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.5.16"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T21:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0640",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zabbix",
            "product" : {
              "product_data" : [ {
                "product_name" : "zabbix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33081",
          "name" : "33081",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24020",
          "name" : "24020",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22321",
          "name" : "22321",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0416",
          "name" : "ADV-2007-0416",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zabbix.com/rn1.1.5.php",
          "name" : "http://www.zabbix.com/rn1.1.5.php",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32038",
          "name" : "zabbix-snmp-bo(32038)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to \"SNMP IP addresses.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zabbix:zabbix:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zabbix:zabbix:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T21:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0641",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "shaffer_solutions_corp",
            "product" : {
              "product_data" : [ {
                "product_name" : "dapcnfsd.dll",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/38119",
          "name" : "38119",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22301",
          "name" : "22301",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c",
          "name" : "http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the EnumPrintersA function in dapcnfsd.dll 0.6.4.0 in Shaffer Solutions (SSC) DiskAccess NFS Client allows remote attackers to execute arbitrary code via a long argument, an issue similar to CVE-2006-5854 and CVE-2007-0444."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shaffer_solutions_corp:dapcnfsd.dll:0.6.4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T21:28Z",
    "lastModifiedDate" : "2008-11-13T06:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0642",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rbl",
            "product" : {
              "product_data" : [ {
                "product_name" : "tforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.00",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2607",
          "name" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2607",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2201",
          "name" : "2201",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001259.html",
          "name" : "20070131 Partial source code verify - \"RBL - ASP\" scripts SQL injection",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/36040",
          "name" : "36040",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458495/100/0/threaded",
          "name" : "20070127 RBL - ASP (scripts with db) SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458560/100/0/threaded",
          "name" : "20070129 RBL - ASP (scripts with db) SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22350",
          "name" : "22350",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31927",
          "name" : "rbl-userpass-sql-injection(31927)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rbl:tforum:2.00:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-01-31T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0643",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bloodshed_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "dev-c++",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.9.9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/38131",
          "name" : "38131",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22315",
          "name" : "22315",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3229",
          "name" : "3229",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bloodshed_software:dev-c\\+\\+:4.9.9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-01-31T21:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0644",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.4_419.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.digitalmunition.com/MOAB-30-01-2007.html",
          "name" : "http://www.digitalmunition.com/MOAB-30-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32710",
          "name" : "32710",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22326",
          "name" : "22326",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAlertSheet Apple AppKit functions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:safari:2.0.4_419.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-01T00:28Z",
    "lastModifiedDate" : "2008-09-05T21:18Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0645",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "iphoto",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://projects.info-pull.com/moab/MOAB-30-01-2007.html",
          "name" : "http://projects.info-pull.com/moab/MOAB-30-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.digitalmunition.com/MOAB-30-01-2007.html",
          "name" : "http://www.digitalmunition.com/MOAB-30-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/32711",
          "name" : "32711",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22326",
          "name" : "22326",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple AppKit functions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:iphoto:6.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-01T00:28Z",
    "lastModifiedDate" : "2008-09-05T21:18Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0646",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "imovie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "safari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=307041",
          "name" : "http://docs.info.apple.com/article.html?artnum=307041",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html",
          "name" : "APPLE-SA-2007-11-14",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/27643",
          "name" : "27643",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.digitalmunition.com/MOAB-30-01-2007.html",
          "name" : "http://www.digitalmunition.com/MOAB-30-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22326",
          "name" : "22326",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/26444",
          "name" : "26444",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-319A.html",
          "name" : "TA07-319A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/3868",
          "name" : "ADV-2007-3868",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.10:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:imovie:6.0.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-01T00:28Z",
    "lastModifiedDate" : "2011-03-07T05:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0647",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.digitalmunition.com/MOAB-30-01-2007.html",
          "name" : "http://www.digitalmunition.com/MOAB-30-01-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/32707",
          "name" : "32707",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22326",
          "name" : "22326",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSBeginAlertSheet Apple AppKit function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-01T00:28Z",
    "lastModifiedDate" : "2008-09-05T21:18Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0648",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "ios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.3(14)t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3(14)t2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3(14)t4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3(14)t5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ym",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(1b)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(1c)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(2)mr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(2)mr1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(2)t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(2)t1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(2)t2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(2)t3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(2)t4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(2)xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(2)xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(2)xb2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(3)t2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(3a)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(3b)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(3d)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(4)mr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(4)t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(4)t2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(5b)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(6)t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(6)t1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(7)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(7a)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(8)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4(9)t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4mr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4sw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xt",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23978",
          "name" : "23978",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017575",
          "name" : "1017575",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-air-20070131-sip.shtml",
          "name" : "http://www.cisco.com/warp/public/707/cisco-air-20070131-sip.shtml",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20070131-sip.shtml",
          "name" : "20070131 SIP Packet Reloads IOS Devices Not Configured for SIP",
          "refsource" : "CISCO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/438176",
          "name" : "VU#438176",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22330",
          "name" : "22330",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0428",
          "name" : "ADV-2007-0428",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31990",
          "name" : "cisco-sip-packet-dos(31990)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5138",
          "name" : "oval:org.mitre.oval:def:5138",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3\\(14\\)t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3\\(14\\)t2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3\\(14\\)t4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3\\(14\\)t5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3ym:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(1\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(1b\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(1c\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(2\\)mr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(2\\)mr1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(2\\)t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(2\\)t1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(2\\)t2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(2\\)t3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(2\\)t4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(2\\)xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(2\\)xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(2\\)xb2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(3\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(3\\)t2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(3a\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(3b\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(3d\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(4\\)mr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(4\\)t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(4\\)t2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(5\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(5b\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(6\\)t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(6\\)t1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(7\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(7a\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(8\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4\\(9\\)t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4mr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4sw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xt:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-01T01:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0649",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openemr",
            "product" : {
              "product_data" : [ {
                "product_name" : "openemr",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.8.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2007-January/001254.html",
          "name" : "20070129 [still bogus] V [mike at carstein.kill-9.pl: Re: Open Conference Systems = 2.8.2 Remote File Inclusion] (fwd)",
          "refsource" : "VIM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://attrition.org/pipermail/vim/2007-January/001258.html",
          "name" : "20070131 VERIFY of RFI and XSS in OpenEMR 2.8.2 (was [still bogus] V [mike at carstein.kill-9.pl: Re: Open Conference Systems = 2.8.2 Remote File Inclusion])",
          "refsource" : "VIM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33603",
          "name" : "33603",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33609",
          "name" : "33609",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2202",
          "name" : "2202",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458306/100/0/threaded",
          "name" : "20070127 Open Conference Systems = 2.8.2 Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458426/100/0/threaded",
          "name" : "20070127 Re: Open Conference Systems = 2.8.2 Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458456/100/0/threaded",
          "name" : "20070129 Fake: Open Conference Systems = 2.8.2 Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458476/100/0/threaded",
          "name" : "20070129 Re: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458486/100/0/threaded",
          "name" : "20070128 Re: Open Conference Systems = 2.8.2 Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458565/100/0/threaded",
          "name" : "20070130 Re: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22346",
          "name" : "22346",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22348",
          "name" : "22348",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in custom/import_xml.php or (b) cross-site scripting (XSS) attacks via the rootdir parameter in interface/login/login_frame.php, via vectors associated with extract operations on the (1) POST and (2) GET superglobal arrays.  NOTE: this issue was originally disputed before the extract behavior was identified in post-disclosure analysis. Also, the original report identified \"Open Conference Systems,\" but this was an error."
        }, {
          "lang" : "en",
          "value" : "Incorrect bug report.  This CVE should have a score of 0 because there are no products affected."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openemr:openemr:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.8.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:M/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "MULTIPLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.2,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-01T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0650",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "makeindex",
            "product" : {
              "product_data" : [ {
                "product_name" : "makeindex",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.14",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/26982",
          "name" : "26982",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30168",
          "name" : "30168",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200709-17.xml",
          "name" : "GLSA-200709-17",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200711-34.xml",
          "name" : "GLSA-200711-34",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200805-13.xml",
          "name" : "GLSA-200805-13",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:109",
          "name" : "MDKSA-2007:109",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23872",
          "name" : "23872",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1706",
          "name" : "ADV-2007-1706",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=225491",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=225491",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32284",
          "name" : "tetex-makeindex-opensty-bo(32284)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1036",
          "name" : "https://issues.rpath.com/browse/RPL-1036",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the open_sty function in mkind.c for makeindex 2.14 in teTeX might allow user-assisted remote attackers to overwrite files and possibly execute arbitrary code via a long filename.  NOTE: other overflows exist but might not be exploitable, such as a heap-based overflow in the check_idx function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:makeindex:makeindex:2.14:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-01T19:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0651",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mailenable",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailenable_professional",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.008",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.009",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.012",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.014",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.015",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.016",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.017",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.72",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.73",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.82",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.83",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.84",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.101",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.102",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.103",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.104",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.105",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.106",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.107",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.108",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.109",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.110",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.111",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.112",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.113",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.114",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.115",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.116",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.351",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33188",
          "name" : "33188",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33189",
          "name" : "33189",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33190",
          "name" : "33190",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23998",
          "name" : "23998",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-38/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-38/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2258",
          "name" : "2258",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.mailenable.com/Professional20-ReleaseNotes.txt",
          "name" : "http://www.mailenable.com/Professional20-ReleaseNotes.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460063/100/0/threaded",
          "name" : "20070214 Secunia Research: MailEnable Web Mail Client MultipleVulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22554",
          "name" : "22554",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0595",
          "name" : "ADV-2007-0595",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32476",
          "name" : "mailenable-email-messages-xss(32476)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32480",
          "name" : "mailenable-id-xss(32480)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.008:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.009:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.010:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.012:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.013:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.014:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.015:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.017:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.72:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.73:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.82:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.83:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.84:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.101:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.102:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.103:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.104:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.105:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.106:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.107:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.108:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.109:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.110:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.111:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.112:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.113:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.114:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.115:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.116:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.351:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-15T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0652",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mailenable",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailenable_professional",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.008",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.009",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.012",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.014",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.015",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.016",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.017",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.72",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.73",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.82",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.83",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.84",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.101",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.102",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.103",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.104",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.105",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.106",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.107",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.108",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.109",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.110",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.111",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.112",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.113",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.114",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.115",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.116",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.351",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33191",
          "name" : "33191",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23998",
          "name" : "23998",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-38/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-38/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2258",
          "name" : "2258",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460063/100/0/threaded",
          "name" : "20070214 Secunia Research: MailEnable Web Mail Client MultipleVulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22554",
          "name" : "22554",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0595",
          "name" : "ADV-2007-0595",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and perform unauthorized actions as arbitrary users via a link or IMG tag."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.008:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.009:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.010:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.012:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.013:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.014:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.015:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.0.017:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.72:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.73:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.82:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.83:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.84:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.101:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.102:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.103:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.104:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.105:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.106:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.107:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.108:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.109:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.110:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.111:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.112:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.113:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.114:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.115:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.116:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:2.351:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-15T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0653",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "x_multimedia_system",
            "product" : {
              "product_data" : [ {
                "product_name" : "x_multimedia_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23986",
          "name" : "23986",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24645",
          "name" : "24645",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24804",
          "name" : "24804",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24889",
          "name" : "24889",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-47/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-47/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1277",
          "name" : "DSA-1277",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:071",
          "name" : "MDKSA-2007:071",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_6_sr.html",
          "name" : "SUSE-SR:2007:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/463408/100/0/threaded",
          "name" : "20070321 Secunia Research: XMMS Integer Overflow and UnderflowVulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23078",
          "name" : "23078",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-445-1",
          "name" : "USN-445-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1057",
          "name" : "ADV-2007-1057",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33205",
          "name" : "xmms-skinbitmap-code-execution(33205)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in X MultiMedia System (xmms) 1.2.10, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via crafted header information in a skin bitmap image, which triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:ia32_64-bit:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:x_multimedia_system:x_multimedia_system:1.2.10:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-21T22:19Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0654",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "x_multimedia_system",
            "product" : {
              "product_data" : [ {
                "product_name" : "x_multimedia_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23986",
          "name" : "23986",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24645",
          "name" : "24645",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24804",
          "name" : "24804",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24889",
          "name" : "24889",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-47/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-47/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1277",
          "name" : "DSA-1277",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:071",
          "name" : "MDKSA-2007:071",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_6_sr.html",
          "name" : "SUSE-SR:2007:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/463408/100/0/threaded",
          "name" : "20070321 Secunia Research: XMMS Integer Overflow and UnderflowVulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23078",
          "name" : "23078",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-445-1",
          "name" : "USN-445-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1057",
          "name" : "ADV-2007-1057",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33203",
          "name" : "xmms-skinbitmap-bo(33203)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer underflow in X MultiMedia System (xmms) 1.2.10 allows user-assisted remote attackers to execute arbitrary code via crafted header information in a skin bitmap image, which results in a stack-based buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:x_multimedia_system:x_multimedia_system:1.2.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-21T22:19Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0655",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microworld_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "escan",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0671.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35732",
          "name" : "35732",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23809",
          "name" : "23809",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-45/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-45/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23759",
          "name" : "23759",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018007",
          "name" : "1018007",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1609",
          "name" : "ADV-2007-1609",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34009",
          "name" : "escan-mwagent-security-bypass(34009)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microworld_technologies:escan:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.0671.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-02T18:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0656",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpbb2-modificat",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpbb2-modificat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36018",
          "name" : "36018",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22320",
          "name" : "22320",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0422",
          "name" : "ADV-2007-0422",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31985",
          "name" : "phpbb2modificat-functions-file-include(31985)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3231",
          "name" : "3231",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb2-modificat:phpbb2-modificat:0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb2-modificat:phpbb2-modificat:0.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-01T22:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0657",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alientrap",
            "product" : {
              "product_data" : [ {
                "product_name" : "nexuiz",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33018",
          "name" : "33018",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23963",
          "name" : "23963",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.alientrap.org/devwiki/index.php?n=Nexuiz.Patch",
          "name" : "http://www.alientrap.org/devwiki/index.php?n=Nexuiz.Patch",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22332",
          "name" : "22332",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0427",
          "name" : "ADV-2007-0427",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32040",
          "name" : "nexuiz-gamedir-information-disclosure(32040)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Nexuiz 2.2.2 allows remote attackers to read and overwrite arbitrary files via the gamedir command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alientrap:nexuiz:2.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-01T22:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0658",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "drupal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7_rev1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "textimage",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://cvs.drupal.org/viewcvs/drupal/contributions/modules/captcha/captcha.module?r1=1.25.2.1&r2=1.25.2.2",
          "name" : "http://cvs.drupal.org/viewcvs/drupal/contributions/modules/captcha/captcha.module?r1=1.25.2.1&r2=1.25.2.2",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://cvs.drupal.org/viewcvs/drupal/contributions/modules/textimage/captcha.inc?r1=1.1&r2=1.1.2.1",
          "name" : "http://cvs.drupal.org/viewcvs/drupal/contributions/modules/textimage/captcha.inc?r1=1.1&r2=1.1.2.1",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://drupal.org/node/114364",
          "name" : "http://drupal.org/node/114364",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://drupal.org/node/114519",
          "name" : "http://drupal.org/node/114519",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/32137",
          "name" : "32137",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32138",
          "name" : "32138",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23983",
          "name" : "23983",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23985",
          "name" : "23985",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22329",
          "name" : "22329",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0431",
          "name" : "ADV-2007-0431",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31984",
          "name" : "textimage-captcha-security-bypass(31984)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31994",
          "name" : "captcha-response-security-bypass(31994)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.7_rev1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:textimage:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:textimage:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-01T22:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0659",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "modxcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "filedownload",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://modxcms.com/forums/index.php/topic,10470.0.html",
          "name" : "http://modxcms.com/forums/index.php/topic,10470.0.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23953",
          "name" : "23953",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.muddydogpaws.com/Home.html",
          "name" : "http://www.muddydogpaws.com/Home.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22327",
          "name" : "22327",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0426",
          "name" : "ADV-2007-0426",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:modxcms:filedownload:1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:modxcms:filedownload:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-01T22:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0660",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dotnetnuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "dotnetnuke_iframe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "03.01.01",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "03.02.00",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36476",
          "name" : "36476",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.dotnetnuke.com/Default.aspx?tabid=825&EntryID=1278",
          "name" : "http://www.dotnetnuke.com/Default.aspx?tabid=825&EntryID=1278",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22334",
          "name" : "22334",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0433",
          "name" : "ADV-2007-0433",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32037",
          "name" : "dotnetnuke-iframe-unspecified-xss(32037)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to \"Pass through values.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dotnetnuke:dotnetnuke_iframe:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "03.01.01"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dotnetnuke:dotnetnuke_iframe:03.02.00:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-01T22:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0661",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "intel",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_southbridge_2_bmc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_southbridge_bmc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server_board_s5000pal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server_board_s5000psl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server_board_s5000vcl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server_board_s5000vsa",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server_board_s5000xal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server_board_s5000xvn",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server_board_sc5400ra",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lz1.intel.com/psirt/advisory.aspx?intelid=INTEL-SA-00012&languageid=en-fr",
          "name" : "http://lz1.intel.com/psirt/advisory.aspx?intelid=INTEL-SA-00012&languageid=en-fr",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33044",
          "name" : "33044",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23989",
          "name" : "23989",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22341",
          "name" : "22341",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0432",
          "name" : "ADV-2007-0432",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Intel Enterprise Southbridge 2 Baseboard Management Controller (BMC), Intel Server Boards 5000XAL, S5000PAL, S5000PSL, S5000XVN, S5000VCL, S5000VSA, SC5400RA, and OEM Firmware for Intel Enterprise Southbridge Baseboard Management Controller before 20070119, when Intelligent Platform Management Interface (IPMI) is enabled, allow remote attackers to connect and issue arbitrary IPMI commands, possibly triggering a denial of service."
        }, {
          "lang" : "en",
          "value" : "The IPMI configuration does not appear to be the cause, but an extra condition for when it's possible.  This is the reason for medium access complexity."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:intel:enterprise_southbridge_2_bmc:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:intel:enterprise_southbridge_bmc:*:*:oem:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:intel:server_board_s5000pal:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:intel:server_board_s5000psl:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:intel:server_board_s5000vcl:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:intel:server_board_s5000vsa:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:intel:server_board_s5000xal:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:intel:server_board_s5000xvn:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:intel:server_board_sc5400ra:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:A/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "ADJACENT_NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 5.5,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-01T22:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0662",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hailboards",
            "product" : {
              "product_data" : [ {
                "product_name" : "hailboards",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33078",
          "name" : "33078",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24002",
          "name" : "24002",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22333",
          "name" : "22333",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0450",
          "name" : "ADV-2007-0450",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31997",
          "name" : "hailboards-usercpviewprofile-file-include(31997)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3236",
          "name" : "3236",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hailboards:hailboards:1.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-01T22:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0663",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eclectic_designs",
            "product" : {
              "product_data" : [ {
                "product_name" : "cascadianfaq",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.vupen.com/english/advisories/2007/0424",
          "name" : "ADV-2007-0424",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eclectic_designs:cascadianfaq:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eclectic_designs:cascadianfaq:4.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-01T22:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0664",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "acme_labs",
            "product" : {
              "product_data" : [ {
                "product_name" : "thttpd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.24",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=142047",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=142047",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/31965",
          "name" : "31965",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24018",
          "name" : "24018",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200701-28.xml",
          "name" : "GLSA-200701-28",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22349",
          "name" : "22349",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:acme_labs:thttpd:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.24"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-02T21:28Z",
    "lastModifiedDate" : "2008-11-15T06:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0665",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ipswitch",
            "product" : {
              "product_data" : [ {
                "product_name" : "ws_ftp_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33602",
          "name" : "33602",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458293/100/0/threaded",
          "name" : "20070126 WS_FTP 2007 Professional SCP handling format string vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22275",
          "name" : "22275",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31865",
          "name" : "wsftp-scphandler-format-string(31865)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the SCP module in Ipswitch WS_FTP 2007 Professional might allow remote attackers to execute arbitrary commands via format string specifiers in the filename, related to the SHELL WS_FTP script command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipswitch:ws_ftp_pro:2007:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-02T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0666",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ipswitch",
            "product" : {
              "product_data" : [ {
                "product_name" : "ws_ftp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33646",
          "name" : "33646",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33647",
          "name" : "33647",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458774/100/0/threaded",
          "name" : "20070201 Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458932/100/0/threaded",
          "name" : "20070202 Re: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458942/100/0/threaded",
          "name" : "20070202 Re[2]: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459023/100/0/threaded",
          "name" : "20070202 Re: Re: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32176",
          "name" : "wsftp-iftpaddu-privilege-escalation(32176)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Ipswitch WS_FTP Server 5.04 allows FTP site administrators to execute arbitrary code on the system via a long input string to the (1) iFTPAddU or (2) iFTPAddH file, or to a (3) edition module."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipswitch:ws_ftp_server:5.04:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-02T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0667",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ledgersmb",
            "product" : {
              "product_data" : [ {
                "product_name" : "ledgersmb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "sql-ledger",
            "product" : {
              "product_data" : [ {
                "product_name" : "sql-ledger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.25",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2217",
          "name" : "2217",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458464/100/0/threaded",
          "name" : "20070127 Arbitrary Code Execution in SQL-Ledger and LedgerSMB through redirects",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459264/100/0/threaded",
          "name" : "20070206 Unofficial SQL-Ledger patch for CVE-2007-0667",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22295",
          "name" : "22295",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0407",
          "name" : "ADV-2007-0407",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ledgersmb:ledgersmb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sql-ledger:sql-ledger:2.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sql-ledger:sql-ledger:2.6.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sql-ledger:sql-ledger:2.6.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sql-ledger:sql-ledger:2.6.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sql-ledger:sql-ledger:2.6.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sql-ledger:sql-ledger:2.6.25:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-02T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0668",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31879",
          "name" : "31879",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23996",
          "name" : "23996",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017582",
          "name" : "1017582",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102699-1",
          "name" : "102699",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22364",
          "name" : "22364",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0462",
          "name" : "ADV-2007-0462",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32140",
          "name" : "solaris-loopbackfs-dos(32140)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1372",
          "name" : "oval:org.mitre.oval:def:1372",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Loopback Filesystem (LOFS) in Sun Solaris 10 allows local users in a non-global zone to move and rename files in a read-only filesystem, which could lead to a denial of service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:N/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.2
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-02T21:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0669",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "twiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "twiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/vulnwatch/2007-q1/0033.html",
          "name" : "20070208 TWiki Security Alert: Arbitrary code execution in session files (CVE-2007-0669)",
          "refsource" : "VULNWATCH",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33168",
          "name" : "33168",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24091",
          "name" : "24091",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2007-0669",
          "name" : "http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2007-0669",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/584436",
          "name" : "VU#584436",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.009.html",
          "name" : "OpenPKG-SA-2007.009",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22378",
          "name" : "22378",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0544",
          "name" : "ADV-2007-0544",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32389",
          "name" : "twiki-cgisession-code-execution(32389)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Twiki 4.0.0 through 4.1.0 allows local users to execute arbitrary Perl code via unknown vectors related to CGI session files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:twiki:twiki:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:twiki:twiki:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:twiki:twiki:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:twiki:twiki:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:twiki:twiki:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:twiki:twiki:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:twiki:twiki:4.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T22:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0670",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://aix.software.ibm.com/aix/efixes/security/README",
          "name" : "ftp://aix.software.ibm.com/aix/efixes/security/README",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23995",
          "name" : "23995",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017583",
          "name" : "1017583",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017607",
          "name" : "1017607",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/31696",
          "name" : "31696",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22370",
          "name" : "22370",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22456",
          "name" : "22456",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0471",
          "name" : "ADV-2007-0471",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IY94301",
          "name" : "IY94301",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IY94368",
          "name" : "IY94368",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32184",
          "name" : "aix-rdist-bo(32184)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via the \"r-commands\", possibly including (1) rdist, (2) rsh, (3) rcp, (4) rsync, and (5) rlogin."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0671",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "access",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "frontpage",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "infopath",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "onenote",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "outlook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "powerpoint",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "project",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "publisher",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "visio",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31901",
          "name" : "31901",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24008",
          "name" : "24008",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017584",
          "name" : "1017584",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://vil.nai.com/vil/content/v_141393.htm",
          "name" : "http://vil.nai.com/vil/content/v_141393.htm",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.avertlabs.com/research/blog/?p=191",
          "name" : "http://www.avertlabs.com/research/blog/?p=191",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/613740",
          "name" : "VU#613740",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.microsoft.com/technet/security/advisory/932553.mspx",
          "name" : "http://www.microsoft.com/technet/security/advisory/932553.mspx",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22383",
          "name" : "22383",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
          "name" : "TA07-044A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0463",
          "name" : "ADV-2007-0463",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015",
          "name" : "MS07-015",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32178",
          "name" : "office-unspecified-code-execution(32178)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A301",
          "name" : "oval:org.mitre.oval:def:301",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:access:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:access:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:access:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:frontpage:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:frontpage:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:frontpage:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:infopath:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:onenote:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:project:2000:sr1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:project:2002:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:project:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:publisher:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:publisher:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:publisher:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visio:2002:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visio:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_viewer:2003:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0672",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ca",
            "product" : {
              "product_data" : [ {
                "product_name" : "brightstor_arcserve_backup_laptops_desktops",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "business_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "desktop_management_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "desktop_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp",
          "name" : "http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458653/100/0/threaded",
          "name" : "20070131 Remote Unauthenticated Resource Exhaustion CA Mobile BackupService",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22339",
          "name" : "22339",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "LGSERVER.EXE in BrightStor Mobile Backup 4.0 allows remote attackers to cause a denial of service (disk consumption and daemon hang) via a value of 0xFFFFFF7F at a certain point in an authentication negotiation packet, which writes a large amount of data to a .USX file in CA_BABLDdata\\Server\\data\\transfer\\."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:business_protection_suite:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:business_protection_suite:2.0:*:microsoft_sbs_premium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:business_protection_suite:2.0:*:microsoft_sbs_standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:desktop_management_suite:11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:desktop_management_suite:11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:desktop_protection_suite:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0673",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ca",
            "product" : {
              "product_data" : [ {
                "product_name" : "brightstor_arcserve_backup_laptops_desktops",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "business_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "desktop_management_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "desktop_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32948",
          "name" : "32948",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2218",
          "name" : "2218",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp",
          "name" : "http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458650/100/0/threaded",
          "name" : "20070131 Remote DOS BrightStor ARCserve Backup for Laptops & Desktops",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22337",
          "name" : "22337",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "LGSERVER.EXE in BrightStor ARCserve Backup for Laptops & Desktops r11.1 allows remote attackers to cause a denial of service (daemon crash) via a value of 0xFFFFFFFF at a certain point in an authentication negotiation packet, which results in an out-of-bounds read."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:business_protection_suite:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:business_protection_suite:2.0:*:microsoft_sbs_premium:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:business_protection_suite:2.0:*:microsoft_sbs_standard:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:desktop_management_suite:11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:desktop_management_suite:11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:desktop_protection_suite:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0674",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_mobile",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003_se",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/",
          "name" : "http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/36148",
          "name" : "36148",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22343",
          "name" : "22343",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0434",
          "name" : "ADV-2007-0434",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32002",
          "name" : "picturesvideos-jpeg-dos(32002)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Pictures and Videos on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows user-assisted remote attackers to cause a denial of service (device hang) via a malformed JPEG file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_mobile:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_mobile:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_mobile:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_mobile:2003_se:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0675",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.technet.com/msrc/archive/2007/01/31/issue-regarding-windows-vista-speech-recognition.aspx",
          "name" : "http://blogs.technet.com/msrc/archive/2007/01/31/issue-regarding-windows-vista-speech-recognition.aspx",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2007-January/004003.html",
          "name" : "[dailydave] 20070130 Vista speach recognition",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2007-January/004005.html",
          "name" : "[dailydave] 20070130 Vista speach recognition",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2007-January/004007.html",
          "name" : "[dailydave] 20070130 Vista speach recognition",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2007-January/004012.html",
          "name" : "[dailydave] 20070131 Vista speach recognition",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=121380194923597&w=2",
          "name" : "HPSBST02344",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30578",
          "name" : "30578",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22359",
          "name" : "22359",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1020232",
          "name" : "1020232",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA08-162B.html",
          "name" : "TA08-162B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1779/references",
          "name" : "ADV-2008-1779",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-032",
          "name" : "MS08-032",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5489",
          "name" : "oval:org.mitre.oval:def:5489",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:32_bit:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0676",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "exo",
            "product" : {
              "product_data" : [ {
                "product_name" : "exophpdesk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36027",
          "name" : "36027",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22338",
          "name" : "22338",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0452",
          "name" : "ADV-2007-0452",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31998",
          "name" : "exophpdesk-faq-sql-injection(31998)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3234",
          "name" : "3234",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that \"magic_quotes_gpc\" is disabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:exo:exophpdesk:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:exo:exophpdesk:1.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0677",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cronosys",
            "product" : {
              "product_data" : [ {
                "product_name" : "cadre_php_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "22020724",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://echo.or.id/adv/adv63-y3dips-2007.txt",
          "name" : "http://echo.or.id/adv/adv63-y3dips-2007.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33631",
          "name" : "33631",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2215",
          "name" : "2215",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458681/100/0/threaded",
          "name" : "20070131 [ECHO_ADV_63$2007] Cadre remote file inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22336",
          "name" : "22336",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0449",
          "name" : "ADV-2007-0449",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32005",
          "name" : "cadre-classquickconfigbrowser-file-include(32005)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3237",
          "name" : "3237",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][framework_path] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cronosys:cadre_php_framework:22020724:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0678",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fullaspsite",
            "product" : {
              "product_data" : [ {
                "product_name" : "asp_hosting_site",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36041",
          "name" : "36041",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22347",
          "name" : "22347",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0453",
          "name" : "ADV-2007-0453",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32020",
          "name" : "fullaspsite-windows-sql-injection(32020)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3233",
          "name" : "3233",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrary SQL commands via the kategori_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fullaspsite:asp_hosting_site:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0679",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nicolas_grandjean",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpmyring",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.0b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.3b",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36039",
          "name" : "36039",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22345",
          "name" : "22345",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0448",
          "name" : "ADV-2007-0448",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32033",
          "name" : "phpmyring-leslangues-file-include(32033)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3238",
          "name" : "3238",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fichier parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicolas_grandjean:phpmyring:4.1.0b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicolas_grandjean:phpmyring:4.1.1b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicolas_grandjean:phpmyring:4.1.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicolas_grandjean:phpmyring:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.1.3b"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0680",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpbb_tweaked",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpbb_tweaked",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33079",
          "name" : "33079",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24001",
          "name" : "24001",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22344",
          "name" : "22344",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0451",
          "name" : "ADV-2007-0451",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xoron.info/bugs/phpbbtweaked.txt",
          "name" : "http://www.xoron.info/bugs/phpbbtweaked.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32024",
          "name" : "phpbbtweaked-functions-file-include(32024)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3235",
          "name" : "3235",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_tweaked:phpbb_tweaked:1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_tweaked:phpbb_tweaked:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0681",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "extcalendar",
            "product" : {
              "product_data" : [ {
                "product_name" : "extcalendar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/38130",
          "name" : "38130",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32035",
          "name" : "extcalendar-profile-security-bypass(32035)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3239",
          "name" : "3239",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:extcalendar:extcalendar:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0682",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jv2",
            "product" : {
              "product_data" : [ {
                "product_name" : "folder_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33077",
          "name" : "33077",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24012",
          "name" : "24012",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22354",
          "name" : "22354",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0447",
          "name" : "ADV-2007-0447",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32043",
          "name" : "jv2gallery-template-file-include(32043)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3240",
          "name" : "3240",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the galleryfilesdir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jv2:folder_gallery:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0683",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "omegaboard_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "omegaboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=117036933022782&w=2",
          "name" : "20070201 Omegaboard v1.0b4 (phpbb_root_path) Remote File Include Exploit",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458825/100/0/threaded",
          "name" : "20070201 Omegaboard v1.0b4 (phpbb_root_path) Remote File Include Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22355",
          "name" : "22355",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0445",
          "name" : "ADV-2007-0445",
          "refsource" : "VUPEN",
          "tags" : [ "Not Applicable" ]
        }, {
          "url" : "http://www.xoron.info/bugs/omegaboard-html.txt",
          "name" : "http://www.xoron.info/bugs/omegaboard-html.txt",
          "refsource" : "MISC",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.xoron.info/bugs/omegaboard-perl.txt",
          "name" : "http://www.xoron.info/bugs/omegaboard-perl.txt",
          "refsource" : "MISC",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32057",
          "name" : "omegaboard-functions-file-include(32057)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3242",
          "name" : "3242",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:omegaboard_project:omegaboard:1.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:omegaboard_project:omegaboard:1.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:omegaboard_project:omegaboard:1.0:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:omegaboard_project:omegaboard:1.0:beta4:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2018-11-29T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0684",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cerulean_portal_system",
            "product" : {
              "product_data" : [ {
                "product_name" : "cerulean_portal_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/458824/100/0/threaded",
          "name" : "20070201 Cerulean Portal System (phpbb_root_path) Remote File Include Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22356",
          "name" : "22356",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0444",
          "name" : "ADV-2007-0444",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xoron.info/bugs/ceruleanportalsystem-html.txt",
          "name" : "http://www.xoron.info/bugs/ceruleanportalsystem-html.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.xoron.info/bugs/ceruleanportalsystem-perl.txt",
          "name" : "http://www.xoron.info/bugs/ceruleanportalsystem-perl.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32058",
          "name" : "cerulean-portal-file-include(32058)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3243",
          "name" : "3243",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cerulean_portal_system:cerulean_portal_system:0.7b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0685",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_mobile",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003_se",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/",
          "name" : "http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/36149",
          "name" : "36149",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22343",
          "name" : "22343",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0434",
          "name" : "ADV-2007-0434",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32001",
          "name" : "ie-mobile-unspecified-dos(32001)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Internet Explorer on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows attackers to cause a denial of service (application crash and device instability) via unspecified vectors, possibly related to a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_mobile:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_mobile:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_mobile:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_mobile:2003_se:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0686",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "intel",
            "product" : {
              "product_data" : [ {
                "product_name" : "2200bg_proset_wireless",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.3.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/37996",
          "name" : "37996",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3224",
          "name" : "3224",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of service (system crash) via crafted disassociation packets, which triggers memory corruption of \"internal kernel structures,\" a different vulnerability than CVE-2006-6651.  NOTE: this issue might overlap CVE-2006-3992."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intel:2200bg_proset_wireless:9.0.3.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0687",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "michelle",
            "product" : {
              "product_data" : [ {
                "product_name" : "l2j_dropcalc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36038",
          "name" : "36038",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22335",
          "name" : "22335",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32003",
          "name" : "l2j-isearch-sql-injection(32003)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3232",
          "name" : "3232",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users to execute arbitrary SQL commands via the itemid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michelle:l2j_dropcalc:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0688",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hunkaray_duyuru",
            "product" : {
              "product_data" : [ {
                "product_name" : "scripti",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34086",
          "name" : "34086",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25581",
          "name" : "25581",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/470744/100/0/threaded",
          "name" : "20070607 H&uuml;nkaray Duyuru Script Remote SQL &#304;njection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24367",
          "name" : "24367",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0446",
          "name" : "ADV-2007-0446",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32042",
          "name" : "hds-oku-sql-injection(32042)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3241",
          "name" : "3241",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hunkaray_duyuru:scripti:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0689",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=117909973216181&w=2",
          "name" : "20070513 MyBB version 1.2.4 Multiple Path Disclosure Vulnerabilities",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/35548",
          "name" : "35548",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35549",
          "name" : "35549",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.netvigilance.com/advisory0017",
          "name" : "http://www.netvigilance.com/advisory0017",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/34155",
          "name" : "34155",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468549/100/0/threaded",
          "name" : "20070513 MyBB version 1.2.4 Multiple Path Disclosure Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34336",
          "name" : "mybb-eventmembercaptcha-info-disclosure(34336)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha.php, and (3) a direct request to inc/datahandlers/event.php, which reveal the installation path in the resulting error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-14T21:19Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0690",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "myevent",
            "product" : {
              "product_data" : [ {
                "product_name" : "myevent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/38336",
          "name" : "38336",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2744",
          "name" : "2744",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.netvigilance.com/advisory0024",
          "name" : "http://www.netvigilance.com/advisory0024",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34272",
          "name" : "34272",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/469831/100/0/threaded",
          "name" : "20070528 myEvent version 1.6 Multiple Path Disclosure Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34542",
          "name" : "myevent-myevent-login-path-disclosure(34542)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "myEvent 1.6 allows remote attackers to obtain sensitive information via (1) a Log In action without a password to login.php, or an invalid (2) view[] or (3) monthno[] parameter to myevent.php, which reveals the path in various error messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:myevent:myevent:1.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-30T20:30Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0691",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-2066.  Reason: This candidate is a duplicate of CVE-2007-2066.  Notes: All CVE users should reference CVE-2007-2066 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2007-05-08T10:19Z",
    "lastModifiedDate" : "2008-09-11T00:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0692",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dgnews",
            "product" : {
              "product_data" : [ {
                "product_name" : "dgnews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/2741",
          "name" : "2741",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.netvigilance.com/advisory0021",
          "name" : "http://www.netvigilance.com/advisory0021",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34226",
          "name" : "34226",
          "refsource" : "OSVDB",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/469826/100/0/threaded",
          "name" : "20070528 DGNews version 2.1 Path Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34540",
          "name" : "dgnews-news-path-disclosure(34540)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "DGNews 2.1 allows remote attackers to obtain sensitive information via a fullnews request to news.php with an invalid newsid parameter, and other unspecified vectors, which reveal the path in various error messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dgnews:dgnews:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-30T20:30Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0693",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dian_gemilang",
            "product" : {
              "product_data" : [ {
                "product_name" : "dgnews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/25438",
          "name" : "25438",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2740",
          "name" : "2740",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.netvigilance.com/advisory0022",
          "name" : "http://www.netvigilance.com/advisory0022",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34227",
          "name" : "34227",
          "refsource" : "OSVDB",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/469828/100/0/threaded",
          "name" : "20070528 DGNews version 2.1 SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24201",
          "name" : "24201",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1981",
          "name" : "ADV-2007-1981",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34539",
          "name" : "dgnews-news-sql-injection(34539)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action.  NOTE: this issue can produce resultant cross-site scripting (XSS)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dian_gemilang:dgnews:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dian_gemilang:dgnews:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-30T20:30Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0694",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dian_gemilang",
            "product" : {
              "product_data" : [ {
                "product_name" : "dgnews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/25438",
          "name" : "25438",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2739",
          "name" : "2739",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.netvigilance.com/advisory0023",
          "name" : "http://www.netvigilance.com/advisory0023",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34228",
          "name" : "34228",
          "refsource" : "OSVDB",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/469829/100/0/threaded",
          "name" : "20070528 DGNews version 2.1 XSS Attack Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24200",
          "name" : "24200",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1981",
          "name" : "ADV-2007-1981",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34537",
          "name" : "dgnews-footer-xss(34537)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dian_gemilang:dgnews:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-05-30T20:30Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0695",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "free_lan_intra_internet_portal",
            "product" : {
              "product_data" : [ {
                "product_name" : "free_lan_intra_internet_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.0.730",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.0.1029",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33649",
          "name" : "33649",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=481131&group_id=98260",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=481131&group_id=98260",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001282.html",
          "name" : "20070203 FLIP SQL injection clarification",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0454",
          "name" : "ADV-2007-0454",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31902",
          "name" : "flip-multiple-sql-injection(31902)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.  NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:0.9.0.730:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:0.9.0.1029:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0_rc2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T22:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0696",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "free_lan_intra_internet_portal",
            "product" : {
              "product_data" : [ {
                "product_name" : "free_lan_intra_internet_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.0.730",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.0.1029",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33650",
          "name" : "33650",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=481131&group_id=98260",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=481131&group_id=98260",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0454",
          "name" : "ADV-2007-0454",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31900",
          "name" : "flip-triggererrortext-xss(31900)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in error messages in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, different vectors than CVE-2007-0611."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:0.9.0.730:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:0.9.0.1029:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T22:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0697",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mentiss_acgv",
            "product" : {
              "product_data" : [ {
                "product_name" : "acgvannu",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33115",
          "name" : "33115",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24072",
          "name" : "24072",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22279",
          "name" : "22279",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0388",
          "name" : "ADV-2007-0388",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31893",
          "name" : "acgv-modif-security-bypass(31893)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3208",
          "name" : "3208",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to templates/modif.html.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mentiss_acgv:acgvannu:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T22:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0698",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mentiss_acgv",
            "product" : {
              "product_data" : [ {
                "product_name" : "acgvannu",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/34666",
          "name" : "34666",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0388",
          "name" : "ADV-2007-0388",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32257",
          "name" : "acgv-modif-sql-injection(32257)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in ACGVannu 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the id_mod parameter to templates/modif.html, and other unspecified vectors.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mentiss_acgv:acgvannu:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-03T22:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0699",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "portail_web_php",
            "product" : {
              "product_data" : [ {
                "product_name" : "portail_web_php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.99",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33633",
          "name" : "33633",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2223",
          "name" : "2223",
          "refsource" : "SREASON",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=480538&group_id=178400",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=480538&group_id=178400",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001269.html",
          "name" : "20070201 Fwd: php web portail [remote file include & local file include]",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458805/100/0/threaded",
          "name" : "20070201 php web portail [remote file include & local file include]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22361",
          "name" : "22361",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0457",
          "name" : "ADV-2007-0457",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32121",
          "name" : "portailwebphp-includes-file-include(32121)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:portail_web_php:portail_web_php:0.99:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:portail_web_php:portail_web_php:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.5.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-04T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0700",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "portail_web_php",
            "product" : {
              "product_data" : [ {
                "product_name" : "portail_web_php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33634",
          "name" : "33634",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001269.html",
          "name" : "20070201 Fwd: php web portail [remote file include & local file include]",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001280.html",
          "name" : "20070202 Local File Inclusion inconclusive in PwP (was Fwd: php web portail [remote file include & local fileinclude])",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001281.html",
          "name" : "20070202 Local File Inclusion inconclusive in PwP (was Fwd: php web portail [remote file include & local fileinclude])",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458805/100/0/threaded",
          "name" : "20070201 php web portail [remote file include & local file include]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22361",
          "name" : "22361",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/27962",
          "name" : "27962",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32115",
          "name" : "portailwebphp-index-file-include(32115)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5182",
          "name" : "5182",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in index.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.  NOTE: this issue was later reported for 2.5.1.1."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:portail_web_php:portail_web_php:2.5.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-04T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0701",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "epistemon",
            "product" : {
              "product_data" : [ {
                "product_name" : "epistemon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31938",
          "name" : "31938",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24003",
          "name" : "24003",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001266.html",
          "name" : "20070201 true: Epistemon 1.0 <= Remote File Include Vulnerability",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22360",
          "name" : "22360",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0459",
          "name" : "ADV-2007-0459",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3247",
          "name" : "3247",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:epistemon:epistemon:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-04T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0702",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpeventman",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpeventman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31936",
          "name" : "31936",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31937",
          "name" : "31937",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24000",
          "name" : "24000",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001264.html",
          "name" : "20070201 true: phpEventMan RFI Vuln.",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22358",
          "name" : "22358",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0460",
          "name" : "ADV-2007-0460",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3246",
          "name" : "3246",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) Shared/controller/text.ctrl.php or (2) UserMan/controller/common.function.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpeventman:phpeventman:1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-04T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0703",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webbuilder",
            "product" : {
              "product_data" : [ {
                "product_name" : "webbuilder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33607",
          "name" : "33607",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001267.html",
          "name" : "20070201 true: WebBuilder <= 2.0 Remote File Include Vulnerability",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0458",
          "name" : "ADV-2007-0458",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3249",
          "name" : "3249",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in library/StageLoader.php in WebBuilder 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[core][module_path] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webbuilder:webbuilder:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-04T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0704",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "somery",
            "product" : {
              "product_data" : [ {
                "product_name" : "somery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33608",
          "name" : "33608",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001265.html",
          "name" : "20070201 True: Somery 0.4.6 (skindir install.php) Remote file include",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/2329",
          "name" : "2329",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter, a different vector than CVE-2006-4669.  NOTE: the documentation says to remove install.php after installation."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:somery:somery:0.4.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-04T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0705",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fenrir",
            "product" : {
              "product_data" : [ {
                "product_name" : "portable_sleipnir",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.45",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "sleipnir",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.49",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/jp/JVN%2393700808/index.html",
          "name" : "JVN#93700808",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32977",
          "name" : "32977",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23927",
          "name" : "23927",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.fenrir.co.jp/press/20070126_2.html",
          "name" : "http://www.fenrir.co.jp/press/20070126_2.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.ipa.go.jp/security/vuln/documents/2006/JVN_93700808.html",
          "name" : "http://www.ipa.go.jp/security/vuln/documents/2006/JVN_93700808.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0364",
          "name" : "ADV-2007-0364",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-zone scripting vulnerability in Sleipnir 2.49 and earlier, and Portable Sleipnir 2.45 and earlier, allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fenrir:portable_sleipnir:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.45"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fenrir:sleipnir:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.49"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-04T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0706",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fenrir",
            "product" : {
              "product_data" : [ {
                "product_name" : "darksky_rss_bar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.28_release3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/jp/JVN%2393700808/index.html",
          "name" : "JVN#93700808",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://www.fenrir.co.jp/press/20070126_2.html",
          "name" : "http://www.fenrir.co.jp/press/20070126_2.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0365",
          "name" : "ADV-2007-0365",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-zone scripting vulnerability in Darksky RSS bar for Internet Explorer before 1.29, RSS bar for Sleipnir before 1.29, and RSS bar for unDonut before 1.29 allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data.  NOTE: some of these details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fenrir:darksky_rss_bar:*:*:internet_explorer:*:*:*:*:*",
          "versionEndIncluding" : "1.28_release3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fenrir:darksky_rss_bar:*:*:sleipnir:*:*:*:*:*",
          "versionEndIncluding" : "1.28_release3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fenrir:darksky_rss_bar:*:*:undonut:*:*:*:*:*",
          "versionEndIncluding" : "1.28_release3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-04T00:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0707",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gom_player",
            "product" : {
              "product_data" : [ {
                "product_name" : "gom_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.12.3375",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33080",
          "name" : "33080",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23994",
          "name" : "23994",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gomplayer.com/forum/viewtopic.html?t=221",
          "name" : "http://www.gomplayer.com/forum/viewtopic.html?t=221",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32164",
          "name" : "gomplayer-asx-bo(32164)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in GOM Player 2.0.12.3375 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the \"ref href\" tag.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gom_player:gom_player:2.0.12.3375:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-04T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0708",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "comodo",
            "product" : {
              "product_data" : [ {
                "product_name" : "comodo_firewall_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.16.174",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1017580",
          "name" : "1017580",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php",
          "name" : "http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458773/100/0/threaded",
          "name" : "20070201 Comodo Multiple insufficient argument validation of hooked SSDT function Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22357",
          "name" : "22357",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32059",
          "name" : "comodofirewallpro-cmdmon-dos(32059)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) before 2.4.16.174 does not validate arguments that originate in user mode for the (1) NtConnectPort and (2) NtCreatePort hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:comodo:comodo_firewall_pro:2.4.16.174:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-04T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0709",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "comodo",
            "product" : {
              "product_data" : [ {
                "product_name" : "comodo_firewall_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.16.174",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1017580",
          "name" : "1017580",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php",
          "name" : "http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458773/100/0/threaded",
          "name" : "20070201 Comodo Multiple insufficient argument validation of hooked SSDT function Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22357",
          "name" : "22357",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32059",
          "name" : "comodofirewallpro-cmdmon-dos(32059)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) 2.4.16.174 and earlier does not validate arguments that originate in user mode for the (1) NtCreateSection, (2) NtOpenProcess, (3) NtOpenSection, (4) NtOpenThread, and (5) NtSetValueKey hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:comodo:comodo_firewall_pro:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.4.16.174"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-04T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0710",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "ichat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305102",
          "name" : "http://docs.info.apple.com/article.html?artnum=305102",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html",
          "name" : "APPLE-SA-2007-02-15",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24198",
          "name" : "24198",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/836024",
          "name" : "VU#836024",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/32713",
          "name" : "32713",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22304",
          "name" : "22304",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017661",
          "name" : "1017661",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:ichat:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-16T19:28Z",
    "lastModifiedDate" : "2008-09-05T21:18Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0711",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305149",
          "name" : "http://docs.info.apple.com/article.html?artnum=305149",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html",
          "name" : "APPLE-SA-2007-03-05",
          "refsource" : "APPLE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33905",
          "name" : "33905",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24359",
          "name" : "24359",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/568689",
          "name" : "VU#568689",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22827",
          "name" : "22827",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017725",
          "name" : "1017725",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-065A.html",
          "name" : "TA07-065A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0825",
          "name" : "ADV-2007-0825",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32814",
          "name" : "quicktime-3gpvideo-overflow(32814)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in Apple QuickTime before 7.1.5, when installed on Windows operating systems, allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP video file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:4.1.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:5.0.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:5.0.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.1.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.1.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.2.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.3.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.4.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.3:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.4:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:-:windows:*:*:*:*:*",
            "versionEndIncluding" : "7.1.4"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-05T22:19Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0712",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305149",
          "name" : "http://docs.info.apple.com/article.html?artnum=305149",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html",
          "name" : "APPLE-SA-2007-03-05",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33904",
          "name" : "33904",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24359",
          "name" : "24359",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/822481",
          "name" : "VU#822481",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22827",
          "name" : "22827",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017725",
          "name" : "1017725",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-065A.html",
          "name" : "TA07-065A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0825",
          "name" : "ADV-2007-0825",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32816",
          "name" : "quicktime-midi-files-bo(32816)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MIDI file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:4.1.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:5.0.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:5.0.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.1.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.1.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.2.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.3.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.4.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.3:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.4:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:-:windows:*:*:*:*:*",
            "versionEndIncluding" : "7.1.4"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:4.1.2:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:5.0.1:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:5.0.2:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.1:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.2:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.1.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.1.1:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.2.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.3.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.4.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.1:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.2:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.1:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.2:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.3:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.4:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.1:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.2:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:-:mac:*:*:*:*:*",
            "versionEndIncluding" : "7.1.4"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.10:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.6:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-05T22:19Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0713",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305149",
          "name" : "http://docs.info.apple.com/article.html?artnum=305149",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html",
          "name" : "APPLE-SA-2007-03-05",
          "refsource" : "APPLE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24359",
          "name" : "24359",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/880561",
          "name" : "VU#880561",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.piotrbania.com/all/adv/quicktime-heap-adv-7.1.txt",
          "name" : "http://www.piotrbania.com/all/adv/quicktime-heap-adv-7.1.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461983/100/0/threaded",
          "name" : "20070306 Apple QuickTime Player Remote Heap Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22827",
          "name" : "22827",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22843",
          "name" : "22843",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017725",
          "name" : "1017725",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-065A.html",
          "name" : "TA07-065A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0825",
          "name" : "ADV-2007-0825",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32817",
          "name" : "quicktime-quicktime-bo(32817)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-05T22:19Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0714",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0003.html",
          "name" : "20070306 Apple QuickTime udta ATOM Integer Overflow",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=305149",
          "name" : "http://docs.info.apple.com/article.html?artnum=305149",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html",
          "name" : "APPLE-SA-2007-03-05",
          "refsource" : "APPLE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33902",
          "name" : "33902",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24359",
          "name" : "24359",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secway.org/advisory/AD20070306.txt",
          "name" : "http://secway.org/advisory/AD20070306.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/861817",
          "name" : "VU#861817",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461999/100/0/threaded",
          "name" : "20070306 Apple QuickTime udta ATOM Integer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/462153/100/0/threaded",
          "name" : "20070307 ZDI-07-010: Apple Quicktime UDTA Parsing Heap Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22827",
          "name" : "22827",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22844",
          "name" : "22844",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017725",
          "name" : "1017725",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-065A.html",
          "name" : "TA07-065A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0825",
          "name" : "ADV-2007-0825",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-010.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-010.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32819",
          "name" : "quicktime-udta-atoms-overflow(32819)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie with a User Data Atom (UDTA) with an Atom size field with a large value."
        }, {
          "lang" : "en",
          "value" : "This vulnerability is addressed in latest version of Quicktime 7.1.5\r\n"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:4.1.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:5.0.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:5.0.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.1.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.1.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.2.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.3.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.4.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.3:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.4:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.0:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.1:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.2:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:-:windows:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:-:windows:*:*:*:*:*",
            "versionEndIncluding" : "7.1.4"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:4.1.2:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:5.0.1:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:5.0.2:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.1:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.0.2:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.1.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.1.1:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.2.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.3.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.4.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.1:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:6.5.2:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.1:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.2:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.3:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.4:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.0:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.1:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.2:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:-:mac:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:-:mac:*:*:*:*:*",
            "versionEndIncluding" : "7.1.4"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.10:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.5.6:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-05T22:19Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0715",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305149",
          "name" : "http://docs.info.apple.com/article.html?artnum=305149",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html",
          "name" : "APPLE-SA-2007-03-05",
          "refsource" : "APPLE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33901",
          "name" : "33901",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24359",
          "name" : "24359",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/448745",
          "name" : "VU#448745",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22827",
          "name" : "22827",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017725",
          "name" : "1017725",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-065A.html",
          "name" : "TA07-065A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0825",
          "name" : "ADV-2007-0825",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32821",
          "name" : "quicktime-pict-file-bo(32821)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-05T22:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0716",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305149",
          "name" : "http://docs.info.apple.com/article.html?artnum=305149",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html",
          "name" : "APPLE-SA-2007-03-05",
          "refsource" : "APPLE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33900",
          "name" : "33900",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24359",
          "name" : "24359",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/642433",
          "name" : "VU#642433",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22827",
          "name" : "22827",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017725",
          "name" : "1017725",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-065A.html",
          "name" : "TA07-065A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0825",
          "name" : "ADV-2007-0825",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32822",
          "name" : "quicktime-qtif-bo(32822)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-05T22:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0717",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305149",
          "name" : "http://docs.info.apple.com/article.html?artnum=305149",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html",
          "name" : "APPLE-SA-2007-03-05",
          "refsource" : "APPLE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33899",
          "name" : "33899",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24359",
          "name" : "24359",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/410993",
          "name" : "VU#410993",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22827",
          "name" : "22827",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017725",
          "name" : "1017725",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-065A.html",
          "name" : "TA07-065A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0825",
          "name" : "ADV-2007-0825",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32823",
          "name" : "quicktime-qtif-overflow(32823)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-05T22:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0718",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305149",
          "name" : "http://docs.info.apple.com/article.html?artnum=305149",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=486",
          "name" : "20070305 Apple QuickTime Color Table ID Heap Corruption Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html",
          "name" : "APPLE-SA-2007-03-05",
          "refsource" : "APPLE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24359",
          "name" : "24359",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/313225",
          "name" : "VU#313225",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/462012/100/0/threaded",
          "name" : "20070306 [Reversemode Advisory] Apple Quicktime Color ID remote heap corruption",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22827",
          "name" : "22827",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22839",
          "name" : "22839",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017725",
          "name" : "1017725",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-065A.html",
          "name" : "TA07-065A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0825",
          "name" : "ADV-2007-0825",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32826",
          "name" : "quicktime-qtif-file-bo(32826)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a QTIF file with a Video Sample Description containing a Color table ID of 0, which triggers memory corruption when QuickTime assumes that a color table exists."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:7.1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-05T22:19Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0719",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/449440",
          "name" : "VU#449440",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/34845",
          "name" : "34845",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22948",
          "name" : "22948",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017751",
          "name" : "1017751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via an image with a crafted ColorSync profile."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-13T21:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0720",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cups",
            "product" : {
              "product_data" : [ {
                "product_name" : "cups",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2785",
          "name" : "FEDORA-2007-1219",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24517",
          "name" : "24517",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24530",
          "name" : "24530",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24660",
          "name" : "24660",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24878",
          "name" : "24878",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24895",
          "name" : "24895",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25119",
          "name" : "25119",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25497",
          "name" : "25497",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26083",
          "name" : "26083",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26413",
          "name" : "26413",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-28.xml",
          "name" : "GLSA-200703-28",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-194.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-194.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:086",
          "name" : "MDKSA-2007:086",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_14_sr.html",
          "name" : "SUSE-SR:2007:014",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_9_sr.html",
          "name" : "SUSE-SR:2007:009",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0123.html",
          "name" : "RHSA-2007:0123",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/463846/100/0/threaded",
          "name" : "20070325 FLEA-2007-0003-1: cups",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22948",
          "name" : "22948",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23127",
          "name" : "23127",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017750",
          "name" : "1017750",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0949",
          "name" : "ADV-2007-0949",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=232243",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=232243",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1173",
          "name" : "https://issues.rpath.com/browse/RPL-1173",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11046",
          "name" : "oval:org.mitre.oval:def:11046",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a \"partially-negotiated\" SSL connection, which prevents other requests from being accepted."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cups:cups:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-13T21:19Z",
    "lastModifiedDate" : "2018-10-16T16:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0721",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34846",
          "name" : "34846",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22948",
          "name" : "22948",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017751",
          "name" : "1017751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted compressed disk image that triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-13T22:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0722",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/124280",
          "name" : "VU#124280",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/34847",
          "name" : "34847",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22948",
          "name" : "22948",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017751",
          "name" : "1017751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted AppleSingleEncoding disk image."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-13T22:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0723",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/557064",
          "name" : "VU#557064",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/34848",
          "name" : "34848",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22948",
          "name" : "22948",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017751",
          "name" : "1017751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the authentication feature for DirectoryService (DS Plug-Ins) for Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote authenticated LDAP users to modify the root password and gain privileges via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 8.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 6.8,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-13T22:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0724",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34855",
          "name" : "34855",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22948",
          "name" : "22948",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017751",
          "name" : "1017751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017942",
          "name" : "1017942",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32973",
          "name" : "macos-hid-privilege-escalation(32973)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-13T22:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0725",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34857",
          "name" : "34857",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort wireless card, allows local users to execute arbitrary code by \"sending malformed control commands.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T16:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0726",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34850",
          "name" : "34850",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22948",
          "name" : "22948",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017756",
          "name" : "1017756",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32975",
          "name" : "macos-openssh-dos(32975)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to cause a denial of service by connecting to the server before SSH has finished creating keys, which causes the keys to be regenerated and can break trust relationships that were based on the original keys."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-13T22:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0727",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0728",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34849",
          "name" : "34849",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22948",
          "name" : "22948",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017751",
          "name" : "1017751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32976",
          "name" : "macos-usbprinter-file-overwrite(32976)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely while initializing a USB printer, which allows local users to create or overwrite arbitrary files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-13T22:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0729",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_preview.app",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/312424",
          "name" : "VU#312424",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/34858",
          "name" : "34858",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017944",
          "name" : "1017944",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_preview.app:3.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T16:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0730",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "server_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34851",
          "name" : "34851",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22948",
          "name" : "22948",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017751",
          "name" : "1017751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32978",
          "name" : "macos-servermanager-authentication-bypass(32978)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Server Manager (servermgrd) in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently validate authentication credentials, which allows remote attackers to bypass authentication and modify system configuration."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:server_manager:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-13T22:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0731",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34852",
          "name" : "34852",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22948",
          "name" : "22948",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017754",
          "name" : "1017754",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32979",
          "name" : "macos-smbfileserver-bo(32979)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 10.4 through 10.4.8 allows context-dependent attackers to execute arbitrary code via a long ACL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-13T22:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0732",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34859",
          "name" : "34859",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017942",
          "name" : "1017942",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via unspecified vectors involving \"obtaining a send right to [the] Mach task port.\""
        }, {
          "lang" : "en",
          "value" : "The vendor has addressed this issue through Mac OS software updates."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T16:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0733",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "imageio",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/873868",
          "name" : "VU#873868",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/34853",
          "name" : "34853",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22948",
          "name" : "22948",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017758",
          "name" : "1017758",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32974",
          "name" : "macos-imageio-code-execution(32974)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in ImageIO in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted RAW image that triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:imageio:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-03-13T22:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0734",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305366",
          "name" : "http://docs.info.apple.com/article.html?artnum=305366",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Apr/msg00000.html",
          "name" : "APPLE-SA-2007-04-09",
          "refsource" : "APPLE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24830",
          "name" : "24830",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23396",
          "name" : "23396",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017889",
          "name" : "1017889",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017942",
          "name" : "1017942",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1308",
          "name" : "ADV-2007-1308",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33527",
          "name" : "airportextreme-airportdisk-info-disclosure(33527)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Firmware Update 7.1, and by Apple Mac OS X 10.3.9 through 10.4.9, does not properly enforce password protection of a USB hard drive, which allows context-dependent attackers to list arbitrary directories or execute arbitrary code, resulting from memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:apple:airport_extreme:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "7.0"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:A/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "ADJACENT_NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 5.5,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-10T22:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0735",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34860",
          "name" : "34860",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017942",
          "name" : "1017942",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Use-after-free vulnerability in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving crafted web pages that trigger certain error conditions that are not properly reported in certain circumstances, resulting in accessing deallocated memory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-04-24T17:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0736",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34861",
          "name" : "34861",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017942",
          "name" : "1017942",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33782",
          "name" : "macos-rpc-code-execution(33782)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via crafted requests to portmap."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T17:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0737",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34862",
          "name" : "34862",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017939",
          "name" : "1017939",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Login Window in Apple Mac OS X 10.3.9 through 10.4.9 does not properly check certain environment variables, which allows local users to gain privileges via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T17:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0738",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34863",
          "name" : "34863",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017939",
          "name" : "1017939",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Login Window in Apple Mac OS X 10.4 through 10.4.9 does not display the screen saver authentication dialog in certain circumstances when waking from sleep, even though the \"require a password to wake the computer from sleep\" option is enabled, which allows local users to bypass authentication controls."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T17:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0739",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34864",
          "name" : "34864",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017939",
          "name" : "1017939",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Login Window in Apple Mac OS X 10.4 through 10.4.9 displays the software update window beneath the loginwindow authentication dialog in certain circumstances related to running scheduled tasks, which allows local users to bypass authentication controls."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T17:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0740",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305530",
          "name" : "http://docs.info.apple.com/article.html?artnum=305530",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/May/msg00004.html",
          "name" : "APPLE-SA-2007-05-24",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25402",
          "name" : "25402",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/35147",
          "name" : "35147",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24144",
          "name" : "24144",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018121",
          "name" : "1018121",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1939",
          "name" : "ADV-2007-1939",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34498",
          "name" : "macos-diskimage-code-execution(34498)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Alias Manager in Apple Mac OS X 10.3.9 and 10.4.9 does not display files with the same name in mounted disk images that have the same name, which might allow user-assisted attackers to trick a user into executing malicious files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-05-24T22:30Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0741",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34865",
          "name" : "34865",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017942",
          "name" : "1017942",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in natd in network_cmds in Apple Mac OS X 10.3.9 through 10.4.9, when Internet Sharing is enabled, allows remote attackers to execute arbitrary code via malformed RTSP packets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T17:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0742",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34866",
          "name" : "34866",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017942",
          "name" : "1017942",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The WebFoundation framework in Apple Mac OS X 10.3.9 and earlier allows subdomain cookies to be accessed by the parent domain, which allows remote attackers to obtain sensitive information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "10.3.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T17:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0743",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34867",
          "name" : "34867",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017942",
          "name" : "1017942",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "URLMount in Apple Mac OS X 10.3.9 through 10.4.9 passes the username and password credentials for mounting filesystems on SMB servers as command line arguments to the mount_sub command, which may allow local users to obtain sensitive information by listing the process."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T17:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0744",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34868",
          "name" : "34868",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T17:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0745",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2007/May/msg00000.html",
          "name" : "APPLE-SA-2007-05-01",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/34869",
          "name" : "34869",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017990",
          "name" : "1017990",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34001",
          "name" : "macos-ftpserver-unauthorized-access(34001)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:A/AC:L/Au:S/C:C/I:C/A:N",
          "accessVector" : "ADJACENT_NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 5.1,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-02T21:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0746",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/969969",
          "name" : "VU#969969",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/34870",
          "name" : "34870",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017942",
          "name" : "1017942",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via a \"crafted SIP packet when initializing an audio/video conference\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T17:19Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0747",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/474969",
          "name" : "VU#474969",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/34871",
          "name" : "34871",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23569",
          "name" : "23569",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017942",
          "name" : "1017942",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-24T17:19Z",
    "lastModifiedDate" : "2013-07-03T15:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0748",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "darwin_streaming_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305495",
          "name" : "http://docs.info.apple.com/article.html?artnum=305495",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=533",
          "name" : "20070510 Apple Darwin Streaming Proxy Multiple Vulnerabilities",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/May/msg00002.html",
          "name" : "APPLE-SA-2007-05-10",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35975",
          "name" : "35975",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25193",
          "name" : "25193",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23918",
          "name" : "23918",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018047",
          "name" : "1018047",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1770",
          "name" : "ADV-2007-1770",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34225",
          "name" : "darwin-trackid-bo(34225)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allows remote attackers to execute arbitrary code via multiple trackID values in a SETUP RTSP request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:darwin_streaming_server:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:darwin_streaming_server:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:darwin_streaming_server:5.5.4:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.2.8:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:darwin_streaming_server:4.1.3:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-13T22:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0749",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "darwin_streaming_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305495",
          "name" : "http://docs.info.apple.com/article.html?artnum=305495",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=533",
          "name" : "20070510 Apple Darwin Streaming Proxy Multiple Vulnerabilities",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/May/msg00002.html",
          "name" : "APPLE-SA-2007-05-10",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://osvdb.org/35976",
          "name" : "35976",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25193",
          "name" : "25193",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23918",
          "name" : "23918",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018047",
          "name" : "1018047",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1770",
          "name" : "ADV-2007-1770",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34222",
          "name" : "darwin-iscommand-bo(34222)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in the is_command function in proxy.c in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allow remote attackers to execute arbitrary code via a long (1) cmd or (2) server value in an RTSP request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:darwin_streaming_server:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:darwin_streaming_server:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:darwin_streaming_server:5.5.4:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.2.8:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:apple:darwin_streaming_server:4.1.3:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-13T22:19Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0750",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305530",
          "name" : "http://docs.info.apple.com/article.html?artnum=305530",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/May/msg00004.html",
          "name" : "APPLE-SA-2007-05-24",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25402",
          "name" : "25402",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/35146",
          "name" : "35146",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24144",
          "name" : "24144",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018114",
          "name" : "1018114",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1939",
          "name" : "ADV-2007-1939",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34499",
          "name" : "macos-pdf-bo(34499)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-05-24T22:30Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0751",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305530",
          "name" : "http://docs.info.apple.com/article.html?artnum=305530",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/May/msg00004.html",
          "name" : "APPLE-SA-2007-05-24",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25402",
          "name" : "25402",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/35145",
          "name" : "35145",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24144",
          "name" : "24144",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018117",
          "name" : "1018117",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1939",
          "name" : "ADV-2007-1939",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34500",
          "name" : "macos-tmpfilesystem-dos(34500)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-24T22:30Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0752",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305530",
          "name" : "http://docs.info.apple.com/article.html?artnum=305530",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=537",
          "name" : "20070524 Apple Computer Mac OS X pppd Plugin Loading Privilege Escalation Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/May/msg00004.html",
          "name" : "APPLE-SA-2007-05-24",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25402",
          "name" : "25402",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/35144",
          "name" : "35144",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24144",
          "name" : "24144",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018124",
          "name" : "1018124",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1939",
          "name" : "ADV-2007-1939",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34503",
          "name" : "macos-pppd-privilege-escalation(34503)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-24T22:30Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0753",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305530",
          "name" : "http://docs.info.apple.com/article.html?artnum=305530",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/May/msg00004.html",
          "name" : "APPLE-SA-2007-05-24",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25402",
          "name" : "25402",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/35143",
          "name" : "35143",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/469882/100/0/threaded",
          "name" : "20070529 Mac OS X vpnd local format string",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/469889/100/0/threaded",
          "name" : "20070529 Re: Mac OS X vpnd local format string",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24144",
          "name" : "24144",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24208",
          "name" : "24208",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018125",
          "name" : "1018125",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1939",
          "name" : "ADV-2007-1939",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34505",
          "name" : "macos-vpnd-format-string(34505)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-24T22:30Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0754",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "quicktime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=304357",
          "name" : "http://docs.info.apple.com/article.html?artnum=304357",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://dvlabs.tippingpoint.com/advisory/TPTI-07-07",
          "name" : "http://dvlabs.tippingpoint.com/advisory/TPTI-07-07",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2703",
          "name" : "2703",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/35574",
          "name" : "35574",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468305/100/0/threaded",
          "name" : "20070511 TPTI-07-07: Apple QuickTime STSD Parsing Heap Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23923",
          "name" : "23923",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34244",
          "name" : "quicktime-stsd-bo(34244)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted Sample Table Sample Descriptor (STSD) atom size in a QuickTime movie."
        }, {
          "lang" : "en",
          "value" : "This vulnerability is addressed in the following product release:\r\nApple, QuickTime, 7.1.3"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.1.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-05-14T21:19Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0756",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "chicken_of_the_vnc",
            "product" : {
              "product_data" : [ {
                "product_name" : "chicken_of_the_vnc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33637",
          "name" : "33637",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2220",
          "name" : "2220",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458907/100/0/threaded",
          "name" : "20070202 Chicken of the VNC 2.0 remote DoS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/466966/100/0/threaded",
          "name" : "20070426 Re: Chicken of the VNC 2.0 remote DoS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22372",
          "name" : "22372",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32166",
          "name" : "cotv-serverinit-dos(32166)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3257",
          "name" : "3257",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large computer-name size value in a ServerInit packet, which triggers a failed malloc and a resulting NULL dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:chicken_of_the_vnc:chicken_of_the_vnc:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0757",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "miguel_nunes",
            "product" : {
              "product_data" : [ {
                "product_name" : "call_of_duty_2_dreamstats_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33095",
          "name" : "33095",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24037",
          "name" : "24037",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001272.html",
          "name" : "20070202 true: DreamStats V 4.2=(index.php)=>Remote File Include",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22371",
          "name" : "22371",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0479",
          "name" : "ADV-2007-0479",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32160",
          "name" : "cod2dreamstats-index-file-include(32160)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3251",
          "name" : "3251",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:miguel_nunes:call_of_duty_2_dreamstats_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0758",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpprobid",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpprobid",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.24",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34667",
          "name" : "34667",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22374",
          "name" : "22374",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32273",
          "name" : "phpprobid-lang-file-include(32273)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in lang.php in PHPProbid 5.24 allows remote attackers to execute arbitrary PHP code via a URL in the SRC attribute of an HTML element in the lang parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpprobid:phpprobid:5.24:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0759",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "umberto_caldera",
            "product" : {
              "product_data" : [ {
                "product_name" : "easymoblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0052.html",
          "name" : "20070201 Remote Sql Injection in EasyMoblog 0.5.1 # 2",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0054.html",
          "name" : "20070201 Remote Sql Injection in EasyMoblog 0.5.1",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33636",
          "name" : "33636",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19370",
          "name" : "19370",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22369",
          "name" : "22369",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog%232.txt",
          "name" : "http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog%232.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog.txt",
          "name" : "http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:umberto_caldera:easymoblog:0.5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2008-11-15T06:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0760",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eqdkp",
            "product" : {
              "product_data" : [ {
                "product_name" : "eqdkp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33112",
          "name" : "33112",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24038",
          "name" : "24038",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/20805",
          "name" : "20805",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32152",
          "name" : "eqdkp-backup-information-disclosure(32152)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3252",
          "name" : "3252",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allows remote attackers to read or modify account names and passwords via a spoofed Referer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eqdkp:eqdkp:1.3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0761",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpbb",
            "product" : {
              "product_data" : [ {
                "product_name" : "ezboard_converter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33645",
          "name" : "33645",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001278.html",
          "name" : "20070202 true: phpBB ezBoard converter 0.2 (ezconvert_dir) Remote File Include Exploit",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0473",
          "name" : "ADV-2007-0473",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xoron.info/bugs/ezconvert.txt",
          "name" : "http://www.xoron.info/bugs/ezconvert.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32157",
          "name" : "ezboard-config-file-include(32157)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3258",
          "name" : "3258",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the ezconvert_dir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb:ezboard_converter:0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0762",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpbb++",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpbb++",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "build_100",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33092",
          "name" : "33092",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24034",
          "name" : "24034",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001279.html",
          "name" : "20070202 phpBB++ Build 100 (phpbb_root_path) Remote File Include Exploit",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22376",
          "name" : "22376",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0472",
          "name" : "ADV-2007-0472",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32159",
          "name" : "phpbbplusplus-functions-file-include(32159)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3259",
          "name" : "3259",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb\\+\\+:phpbb\\+\\+:build_100:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0763",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "f3site",
            "product" : {
              "product_data" : [ {
                "product_name" : "f3site",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34668",
          "name" : "34668",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22379",
          "name" : "22379",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32188",
          "name" : "f3site-autor-xss(32188)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3255",
          "name" : "3255",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the news comment functionality in F3Site 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the Autor field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f3site:f3site:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0764",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "f3site",
            "product" : {
              "product_data" : [ {
                "product_name" : "f3site",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34669",
          "name" : "34669",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32189",
          "name" : "f3site-adm-file-upload(32189)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3255",
          "name" : "3255",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in F3Site 2.1 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP scripts via GIF86 header in a file in the uplf parameter, which can be later accessed via a relative pathname in the dir parameter in adm.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f3site:f3site:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0765",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "db_masters_multimedia",
            "product" : {
              "product_data" : [ {
                "product_name" : "curium_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.03",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33111",
          "name" : "33111",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24032",
          "name" : "24032",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22373",
          "name" : "22373",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0474",
          "name" : "ADV-2007-0474",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32148",
          "name" : "curium-news-sql-injection(32148)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3256",
          "name" : "3256",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in news.php in dB Masters Curium CMS 1.03 and earlier allows remote attackers to execute arbitrary SQL commands via the c_id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:db_masters_multimedia:curium_cms:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.03"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0766",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "remotesoft",
            "product" : {
              "product_data" : [ {
                "product_name" : ".net_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34755",
          "name" : "34755",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22377",
          "name" : "22377",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32182",
          "name" : "netexplorer-char-bo(32182)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3254",
          "name" : "3254",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:remotesoft:.net_explorer:2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0767",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phorum",
            "product" : {
              "product_data" : [ {
                "product_name" : "phorum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.17",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34727",
          "name" : "34727",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.phorum.org/phorum5/read.php?12,119757",
          "name" : "http://www.phorum.org/phorum5/read.php?12,119757",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0410",
          "name" : "ADV-2007-0410",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/44201",
          "name" : "phorum-core-xss(44201)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the core in Phorum before 5.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phorum:phorum:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.1.17"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0768",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "yahoo",
            "product" : {
              "product_data" : [ {
                "product_name" : "messenger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.0.209",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31674",
          "name" : "31674",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23928",
          "name" : "23928",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458225/100/0/threaded",
          "name" : "20070126 Cross-site Scripting with Local Privilege Vulnerability in Yahoo Messenger",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458305/100/0/threaded",
          "name" : "20070127 RE: Cross-site Scripting with Local Privilege Vulnerability in Yahoo Messenger",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458494/100/0/threaded",
          "name" : "20070127 Re: Cross-site Scripting with Local Privilege Vulnerability in Yahoo Messenger",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22269",
          "name" : "22269",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields.  NOTE: some of these details are obtained from third party information."
        }, {
          "lang" : "en",
          "value" : "Access Complexity: Successful exploitation requires that the attacker is in the messenger list of the target."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.1.0.209"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0769",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phorum",
            "product" : {
              "product_data" : [ {
                "product_name" : "phorum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.18",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.phorum.org/phorum5/read.php?12,119757",
          "name" : "http://www.phorum.org/phorum5/read.php?12,119757",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458461/100/0/threaded",
          "name" : "20070129 Phorum HTML Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458467/100/0/threaded",
          "name" : "20070129 Re: Phorum HTML Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22297",
          "name" : "22297",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0410",
          "name" : "ADV-2007-0410",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Cross-site scripting (XSS) vulnerability in register.php in Phorum 5.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: the vendor disputes this vulnerability, stating that \"The characters are escaped properly.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phorum:phorum:5.1.18:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0770",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "graphicsmagick",
            "product" : {
              "product_data" : [ {
                "product_name" : "graphicsmagick",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "imagemagick",
            "product" : {
              "product_data" : [ {
                "product_name" : "imagemagick",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3.3.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24167",
          "name" : "24167",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24196",
          "name" : "24196",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1260",
          "name" : "DSA-1260",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:041",
          "name" : "MDKSA-2007:041",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_3_sr.html",
          "name" : "SUSE-SR:2007:003",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/31911",
          "name" : "31911",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459507/100/0/threaded",
          "name" : "20070208 rPSA-2007-0029-1 ImageMagick",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-422-1",
          "name" : "USN-422-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1034",
          "name" : "https://issues.rpath.com/browse/RPL-1034",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:graphicsmagick:graphicsmagick:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:imagemagick:imagemagick:6.3.3.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-12T20:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0771",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35927",
          "name" : "35927",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25080",
          "name" : "25080",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017979",
          "name" : "1017979",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0169.html",
          "name" : "RHSA-2007:0169",
          "refsource" : "REDHAT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23720",
          "name" : "23720",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=227952",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=227952",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=228816",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=228816",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34128",
          "name" : "kernel-utracesupport-dos(34128)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9447",
          "name" : "oval:org.mitre.oval:def:9447",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial of service (system hang) related to \"MT exec + utrace_attach spin failure mode,\" as demonstrated by ptrace-thrash.c."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:5.0:*:desktop:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:5.0:*:desktop_workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:5.0:*:server:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-02T22:19Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0772",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.57",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://fedoranews.org/cms/node/2739",
          "name" : "FEDORA-2007-277",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2740",
          "name" : "FEDORA-2007-291",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.1",
          "name" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.1",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33022",
          "name" : "33022",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24201",
          "name" : "24201",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24215",
          "name" : "24215",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24400",
          "name" : "24400",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24482",
          "name" : "24482",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24547",
          "name" : "24547",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24752",
          "name" : "24752",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24777",
          "name" : "24777",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25691",
          "name" : "25691",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:060",
          "name" : "MDKSA-2007:060",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:078",
          "name" : "MDKSA-2007:078",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_18_kernel.html",
          "name" : "SUSE-SA:2007:018",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_21_kernel.html",
          "name" : "SUSE-SA:2007:021",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/471457",
          "name" : "20070615 rPSA-2007-0124-1 kernel xen",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22625",
          "name" : "22625",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-451-1",
          "name" : "USN-451-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0660",
          "name" : "ADV-2007-0660",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32578",
          "name" : "kernel-nfsaclsvc-dos(32578)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1063",
          "name" : "https://issues.rpath.com/browse/RPL-1063",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Linux kernel 2.6.13 and other versions before 2.6.20.1 allows remote attackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS request that triggers a free of an incorrect pointer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.43:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.45:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.46:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.49:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.55:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.56:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.57:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.59:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.6.20"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-20T17:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0773",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=243252",
          "name" : "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=243252",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://osvdb.org/37128",
          "name" : "37128",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0488.html",
          "name" : "RHSA-2007:0488",
          "refsource" : "REDHAT",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/25838",
          "name" : "25838",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26289",
          "name" : "26289",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/27227",
          "name" : "27227",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_53_kernel.html",
          "name" : "SUSE-SA:2007:053",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11267",
          "name" : "oval:org.mitre.oval:def:11267",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Linux kernel before 2.6.9-42.0.8 in Red Hat 4.4 allows local users to cause a denial of service (kernel OOPS from null dereference) via fput in a 32-bit ioctl on 64-bit x86 systems, an incomplete fix of CVE-2005-3044.1."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:4.4:*:as:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:4.4:*:es:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:4.4:*:ws:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:4.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-06-26T18:30Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0774",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "tomcat_jk_web_server_connector",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.20",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795",
          "name" : "SSRT071447",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24398",
          "name" : "24398",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24558",
          "name" : "24558",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/27037",
          "name" : "27037",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28711",
          "name" : "28711",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017719",
          "name" : "1017719",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://tomcat.apache.org/connectors-doc/miscellaneous/changelog.html",
          "name" : "http://tomcat.apache.org/connectors-doc/miscellaneous/changelog.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://tomcat.apache.org/security-jk.html",
          "name" : "http://tomcat.apache.org/security-jk.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a008093f040.shtml",
          "name" : "20080130 Cisco Wireless Control System Tomcat mod_jk.so Vulnerability",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-16.xml",
          "name" : "GLSA-200703-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0096.html",
          "name" : "RHSA-2007:0096",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461734/100/0/threaded",
          "name" : "20070302 ZDI-07-008: Apache Tomcat JK Web Server Connector Long URL Stack Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22791",
          "name" : "22791",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0809",
          "name" : "ADV-2007-0809",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/3386",
          "name" : "ADV-2007-3386",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0331",
          "name" : "ADV-2008-0331",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-008.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-008.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32794",
          "name" : "tomcat-mapuritoworker-bo(32794)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190413 svn commit: r1857494 [18/20] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190415 svn commit: r1857582 [20/22] - in /tomcat/site/trunk: docs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190325 svn commit: r1856174 [25/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190319 svn commit: r1855831 [26/30] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r5c616dfc49156e4b06ffab842800c80f4425924d0f20c452c127a53c@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200213 svn commit: r1873980 [30/34] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200203 svn commit: r1873527 [26/30] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5513",
          "name" : "oval:org.mitre.oval:def:5513",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat_jk_web_server_connector:1.2.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat_jk_web_server_connector:1.2.20:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-03-04T22:19Z",
    "lastModifiedDate" : "2019-04-15T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0775",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc",
          "name" : "20070202-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc",
          "name" : "20070301-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2713",
          "name" : "FEDORA-2007-281",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2728",
          "name" : "FEDORA-2007-293",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2747",
          "name" : "FEDORA-2007-308",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2749",
          "name" : "FEDORA-2007-309",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742",
          "name" : "HPSBUX02153",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html",
          "name" : "SUSE-SA:2007:019",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0077.html",
          "name" : "RHSA-2007:0077",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24205",
          "name" : "24205",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24238",
          "name" : "24238",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24252",
          "name" : "24252",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24287",
          "name" : "24287",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24290",
          "name" : "24290",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24293",
          "name" : "24293",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24320",
          "name" : "24320",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24328",
          "name" : "24328",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24333",
          "name" : "24333",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24342",
          "name" : "24342",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24343",
          "name" : "24343",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24384",
          "name" : "24384",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24389",
          "name" : "24389",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24393",
          "name" : "24393",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24395",
          "name" : "24395",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24406",
          "name" : "24406",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24410",
          "name" : "24410",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24437",
          "name" : "24437",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24455",
          "name" : "24455",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24456",
          "name" : "24456",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24457",
          "name" : "24457",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24522",
          "name" : "24522",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24650",
          "name" : "24650",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25588",
          "name" : "25588",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-04.xml",
          "name" : "GLSA-200703-04",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-18.xml",
          "name" : "GLSA-200703-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131",
          "name" : "SSA:2007-066-05",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947",
          "name" : "SSA:2007-066-04",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851",
          "name" : "SSA:2007-066-03",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1336",
          "name" : "DSA-1336",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml",
          "name" : "GLSA-200703-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/761756",
          "name" : "VU#761756",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:050",
          "name" : "MDKSA-2007:050",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:052",
          "name" : "MDKSA-2007:052",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2007/mfsa2007-01.html",
          "name" : "http://www.mozilla.org/security/announce/2007/mfsa2007-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_22_mozilla.html",
          "name" : "SUSE-SA:2007:022",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32114",
          "name" : "32114",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0078.html",
          "name" : "RHSA-2007:0078",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0079.html",
          "name" : "RHSA-2007:0079",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0097.html",
          "name" : "RHSA-2007:0097",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0108.html",
          "name" : "RHSA-2007:0108",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461336/100/0/threaded",
          "name" : "20070226 rPSA-2007-0040-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461809/100/0/threaded",
          "name" : "20070303 rPSA-2007-0040-3 firefox thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22694",
          "name" : "22694",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017698",
          "name" : "1017698",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-428-1",
          "name" : "USN-428-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-431-1",
          "name" : "USN-431-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0718",
          "name" : "ADV-2007-0718",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0719",
          "name" : "ADV-2007-0719",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0083",
          "name" : "ADV-2008-0083",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32704",
          "name" : "mozilla-multiple-layout-code-execution(32704)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1081",
          "name" : "https://issues.rpath.com/browse/RPL-1081",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1103",
          "name" : "https://issues.rpath.com/browse/RPL-1103",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10012",
          "name" : "oval:org.mitre.oval:def:10012",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allow remote attackers to cause a denial of service (crash) and potentially execute arbitrary code via certain vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0:beta_1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-26T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0776",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.7",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://fedoranews.org/cms/node/2713",
          "name" : "FEDORA-2007-281",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2728",
          "name" : "FEDORA-2007-293",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2747",
          "name" : "FEDORA-2007-308",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2749",
          "name" : "FEDORA-2007-309",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742",
          "name" : "HPSBUX02153",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html",
          "name" : "SUSE-SA:2007:019",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24205",
          "name" : "24205",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24238",
          "name" : "24238",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24252",
          "name" : "24252",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24293",
          "name" : "24293",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24320",
          "name" : "24320",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24328",
          "name" : "24328",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24333",
          "name" : "24333",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24384",
          "name" : "24384",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24389",
          "name" : "24389",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24393",
          "name" : "24393",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24406",
          "name" : "24406",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24410",
          "name" : "24410",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24437",
          "name" : "24437",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24455",
          "name" : "24455",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24456",
          "name" : "24456",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24457",
          "name" : "24457",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24522",
          "name" : "24522",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-04.xml",
          "name" : "GLSA-200703-04",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-18.xml",
          "name" : "GLSA-200703-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131",
          "name" : "SSA:2007-066-05",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947",
          "name" : "SSA:2007-066-04",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851",
          "name" : "SSA:2007-066-03",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml",
          "name" : "GLSA-200703-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/551436",
          "name" : "VU#551436",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:052",
          "name" : "MDKSA-2007:052",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2007/mfsa2007-01.html",
          "name" : "http://www.mozilla.org/security/announce/2007/mfsa2007-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_22_mozilla.html",
          "name" : "SUSE-SA:2007:022",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32113",
          "name" : "32113",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461336/100/0/threaded",
          "name" : "20070226 rPSA-2007-0040-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461809/100/0/threaded",
          "name" : "20070303 rPSA-2007-0040-3 firefox thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22694",
          "name" : "22694",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017698",
          "name" : "1017698",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-428-1",
          "name" : "USN-428-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-431-1",
          "name" : "USN-431-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0718",
          "name" : "ADV-2007-0718",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0719",
          "name" : "ADV-2007-0719",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0083",
          "name" : "ADV-2008-0083",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=360645",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=360645",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32698",
          "name" : "firefox-strokewidth-bo(32698)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1081",
          "name" : "https://issues.rpath.com/browse/RPL-1081",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.0.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.7"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-26T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0777",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc",
          "name" : "20070202-01-P",
          "refsource" : "SGI",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc",
          "name" : "20070301-01-P",
          "refsource" : "SGI",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2713",
          "name" : "FEDORA-2007-281",
          "refsource" : "FEDORA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2728",
          "name" : "FEDORA-2007-293",
          "refsource" : "FEDORA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2747",
          "name" : "FEDORA-2007-308",
          "refsource" : "FEDORA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2749",
          "name" : "FEDORA-2007-309",
          "refsource" : "FEDORA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742",
          "name" : "HPSBUX02153",
          "refsource" : "HP",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html",
          "name" : "SUSE-SA:2007:019",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0077.html",
          "name" : "RHSA-2007:0077",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24205",
          "name" : "24205",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24238",
          "name" : "24238",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24252",
          "name" : "24252",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24287",
          "name" : "24287",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24290",
          "name" : "24290",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24293",
          "name" : "24293",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24320",
          "name" : "24320",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24328",
          "name" : "24328",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24333",
          "name" : "24333",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24342",
          "name" : "24342",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24343",
          "name" : "24343",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24384",
          "name" : "24384",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24389",
          "name" : "24389",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24393",
          "name" : "24393",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24395",
          "name" : "24395",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24406",
          "name" : "24406",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24410",
          "name" : "24410",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24437",
          "name" : "24437",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24455",
          "name" : "24455",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24456",
          "name" : "24456",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24457",
          "name" : "24457",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24522",
          "name" : "24522",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24650",
          "name" : "24650",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-04.xml",
          "name" : "GLSA-200703-04",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-18.xml",
          "name" : "GLSA-200703-18",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131",
          "name" : "SSA:2007-066-05",
          "refsource" : "SLACKWARE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947",
          "name" : "SSA:2007-066-04",
          "refsource" : "SLACKWARE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851",
          "name" : "SSA:2007-066-03",
          "refsource" : "SLACKWARE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml",
          "name" : "GLSA-200703-08",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/269484",
          "name" : "VU#269484",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:050",
          "name" : "MDKSA-2007:050",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:052",
          "name" : "MDKSA-2007:052",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2007/mfsa2007-01.html",
          "name" : "http://www.mozilla.org/security/announce/2007/mfsa2007-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_22_mozilla.html",
          "name" : "SUSE-SA:2007:022",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.osvdb.org/32115",
          "name" : "32115",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0078.html",
          "name" : "RHSA-2007:0078",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0079.html",
          "name" : "RHSA-2007:0079",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0097.html",
          "name" : "RHSA-2007:0097",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0108.html",
          "name" : "RHSA-2007:0108",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461336/100/0/threaded",
          "name" : "20070226 rPSA-2007-0040-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461809/100/0/threaded",
          "name" : "20070303 rPSA-2007-0040-3 firefox thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22694",
          "name" : "22694",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017698",
          "name" : "1017698",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-428-1",
          "name" : "USN-428-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-431-1",
          "name" : "USN-431-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0718",
          "name" : "ADV-2007-0718",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0719",
          "name" : "ADV-2007-0719",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0083",
          "name" : "ADV-2008-0083",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32699",
          "name" : "mozilla-multiple-javascript-code-execution(32699)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1081",
          "name" : "https://issues.rpath.com/browse/RPL-1081",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1103",
          "name" : "https://issues.rpath.com/browse/RPL-1103",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11331",
          "name" : "oval:org.mitre.oval:def:11331",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation in Thunderbird requires that JavaScript be enabled in mail which is not the default setting."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.5",
          "versionEndExcluding" : "1.5.0.10"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0",
          "versionEndExcluding" : "2.0.0.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "1.0.8"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "1.5.0.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-26T19:28Z",
    "lastModifiedDate" : "2019-10-09T22:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0778",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc",
          "name" : "20070202-01-P",
          "refsource" : "SGI",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc",
          "name" : "20070301-01-P",
          "refsource" : "SGI",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2713",
          "name" : "FEDORA-2007-281",
          "refsource" : "FEDORA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2728",
          "name" : "FEDORA-2007-293",
          "refsource" : "FEDORA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742",
          "name" : "HPSBUX02153",
          "refsource" : "HP",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html",
          "name" : "SUSE-SA:2007:019",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0077.html",
          "name" : "RHSA-2007:0077",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24205",
          "name" : "24205",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24238",
          "name" : "24238",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24287",
          "name" : "24287",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24290",
          "name" : "24290",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24293",
          "name" : "24293",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24320",
          "name" : "24320",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24328",
          "name" : "24328",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24333",
          "name" : "24333",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24342",
          "name" : "24342",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24343",
          "name" : "24343",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24384",
          "name" : "24384",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24393",
          "name" : "24393",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24395",
          "name" : "24395",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24437",
          "name" : "24437",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24455",
          "name" : "24455",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24457",
          "name" : "24457",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24650",
          "name" : "24650",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25588",
          "name" : "25588",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-04.xml",
          "name" : "GLSA-200703-04",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017699",
          "name" : "1017699",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131",
          "name" : "SSA:2007-066-05",
          "refsource" : "SLACKWARE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851",
          "name" : "SSA:2007-066-03",
          "refsource" : "SLACKWARE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1336",
          "name" : "DSA-1336",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml",
          "name" : "GLSA-200703-08",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:050",
          "name" : "MDKSA-2007:050",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2007/mfsa2007-03.html",
          "name" : "http://www.mozilla.org/security/announce/2007/mfsa2007-03.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_22_mozilla.html",
          "name" : "SUSE-SA:2007:022",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.osvdb.org/32110",
          "name" : "32110",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0078.html",
          "name" : "RHSA-2007:0078",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0079.html",
          "name" : "RHSA-2007:0079",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0097.html",
          "name" : "RHSA-2007:0097",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0108.html",
          "name" : "RHSA-2007:0108",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461336/100/0/threaded",
          "name" : "20070226 rPSA-2007-0040-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461809/100/0/threaded",
          "name" : "20070303 rPSA-2007-0040-3 firefox thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22694",
          "name" : "22694",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-428-1",
          "name" : "USN-428-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0718",
          "name" : "ADV-2007-0718",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0083",
          "name" : "ADV-2008-0083",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=347852",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=347852",
          "refsource" : "MISC",
          "tags" : [ "Issue Tracking" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32671",
          "name" : "mozilla-diskcache-information-disclosure(32671)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1081",
          "name" : "https://issues.rpath.com/browse/RPL-1081",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1103",
          "name" : "https://issues.rpath.com/browse/RPL-1103",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9151",
          "name" : "oval:org.mitre.oval:def:9151",
          "refsource" : "OVAL",
          "tags" : [ "Broken Link" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.5",
          "versionEndExcluding" : "1.5.0.10"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0",
          "versionEndExcluding" : "2.0.0.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "1.0.8"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-26T20:28Z",
    "lastModifiedDate" : "2019-10-09T22:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0779",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9_rc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.99",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc",
          "name" : "20070202-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc",
          "name" : "20070301-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2713",
          "name" : "FEDORA-2007-281",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2728",
          "name" : "FEDORA-2007-293",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742",
          "name" : "HPSBUX02153",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html",
          "name" : "SUSE-SA:2007:019",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32109",
          "name" : "32109",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0077.html",
          "name" : "RHSA-2007:0077",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24205",
          "name" : "24205",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24238",
          "name" : "24238",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24287",
          "name" : "24287",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24290",
          "name" : "24290",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24293",
          "name" : "24293",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24320",
          "name" : "24320",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24328",
          "name" : "24328",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24333",
          "name" : "24333",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24342",
          "name" : "24342",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24343",
          "name" : "24343",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24384",
          "name" : "24384",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24393",
          "name" : "24393",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24395",
          "name" : "24395",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24437",
          "name" : "24437",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24455",
          "name" : "24455",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24457",
          "name" : "24457",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24650",
          "name" : "24650",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-04.xml",
          "name" : "GLSA-200703-04",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131",
          "name" : "SSA:2007-066-05",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851",
          "name" : "SSA:2007-066-03",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml",
          "name" : "GLSA-200703-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:050",
          "name" : "MDKSA-2007:050",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2007/mfsa2007-04.html",
          "name" : "http://www.mozilla.org/security/announce/2007/mfsa2007-04.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_22_mozilla.html",
          "name" : "SUSE-SA:2007:022",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0078.html",
          "name" : "RHSA-2007:0078",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0079.html",
          "name" : "RHSA-2007:0079",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0097.html",
          "name" : "RHSA-2007:0097",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0108.html",
          "name" : "RHSA-2007:0108",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461336/100/0/threaded",
          "name" : "20070226 rPSA-2007-0040-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461809/100/0/threaded",
          "name" : "20070303 rPSA-2007-0040-3 firefox thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22694",
          "name" : "22694",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017700",
          "name" : "1017700",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-428-1",
          "name" : "USN-428-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0718",
          "name" : "ADV-2007-0718",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0083",
          "name" : "ADV-2008-0083",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=361298",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=361298",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1081",
          "name" : "https://issues.rpath.com/browse/RPL-1081",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1103",
          "name" : "https://issues.rpath.com/browse/RPL-1103",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8757",
          "name" : "oval:org.mitre.oval:def:8757",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9_rc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0:beta_1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:dev:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0.99:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-26T20:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0780",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc",
          "name" : "20070202-01-P",
          "refsource" : "SGI",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc",
          "name" : "20070301-01-P",
          "refsource" : "SGI",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2713",
          "name" : "FEDORA-2007-281",
          "refsource" : "FEDORA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2728",
          "name" : "FEDORA-2007-293",
          "refsource" : "FEDORA",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742",
          "name" : "HPSBUX02153",
          "refsource" : "HP",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html",
          "name" : "SUSE-SA:2007:019",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0077.html",
          "name" : "RHSA-2007:0077",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24205",
          "name" : "24205",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24238",
          "name" : "24238",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24287",
          "name" : "24287",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24290",
          "name" : "24290",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24293",
          "name" : "24293",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24320",
          "name" : "24320",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24328",
          "name" : "24328",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24333",
          "name" : "24333",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24342",
          "name" : "24342",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24343",
          "name" : "24343",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24384",
          "name" : "24384",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24393",
          "name" : "24393",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24395",
          "name" : "24395",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24437",
          "name" : "24437",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24455",
          "name" : "24455",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24457",
          "name" : "24457",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24650",
          "name" : "24650",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-04.xml",
          "name" : "GLSA-200703-04",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131",
          "name" : "SSA:2007-066-05",
          "refsource" : "SLACKWARE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851",
          "name" : "SSA:2007-066-03",
          "refsource" : "SLACKWARE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml",
          "name" : "GLSA-200703-08",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:050",
          "name" : "MDKSA-2007:050",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2007/mfsa2007-05.html",
          "name" : "http://www.mozilla.org/security/announce/2007/mfsa2007-05.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_22_mozilla.html",
          "name" : "SUSE-SA:2007:022",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.osvdb.org/32107",
          "name" : "32107",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0078.html",
          "name" : "RHSA-2007:0078",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0079.html",
          "name" : "RHSA-2007:0079",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0097.html",
          "name" : "RHSA-2007:0097",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0108.html",
          "name" : "RHSA-2007:0108",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461336/100/0/threaded",
          "name" : "20070226 rPSA-2007-0040-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461809/100/0/threaded",
          "name" : "20070303 rPSA-2007-0040-3 firefox thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22694",
          "name" : "22694",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017702",
          "name" : "1017702",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-428-1",
          "name" : "USN-428-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0718",
          "name" : "ADV-2007-0718",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=354973",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=354973",
          "refsource" : "MISC",
          "tags" : [ "Issue Tracking", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32667",
          "name" : "mozilla-dataurl-xss(32667)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1081",
          "name" : "https://issues.rpath.com/browse/RPL-1081",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1103",
          "name" : "https://issues.rpath.com/browse/RPL-1103",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9884",
          "name" : "oval:org.mitre.oval:def:9884",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.5",
          "versionEndExcluding" : "1.5.0.10"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0",
          "versionEndExcluding" : "2.0.0.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "1.0.8"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-26T20:28Z",
    "lastModifiedDate" : "2019-10-09T22:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0784",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rbl",
            "product" : {
              "product_data" : [ {
                "product_name" : "tpassword",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2607",
          "name" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2607",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2225",
          "name" : "2225",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001259.html",
          "name" : "20070131 Partial source code verify - \"RBL - ASP\" scripts SQL injection",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458495/100/0/threaded",
          "name" : "20070127 RBL - ASP (scripts with db) SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458560/100/0/threaded",
          "name" : "20070129 RBL - ASP (scripts with db) SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in login.asp for tPassword in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rbl:tpassword:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T17:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0785",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "flipsource",
            "product" : {
              "product_data" : [ {
                "product_name" : "flip",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.01-final_1.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35748",
          "name" : "35748",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22385",
          "name" : "22385",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0476",
          "name" : "ADV-2007-0476",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32174",
          "name" : "flip-previewtheme-file-include(32174)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3266",
          "name" : "3266",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:flipsource:flip:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.01-final_1.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0786",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "noname_media",
            "product" : {
              "product_data" : [ {
                "product_name" : "photo_galerie_standard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33089",
          "name" : "33089",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24029",
          "name" : "24029",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22384",
          "name" : "22384",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0475",
          "name" : "ADV-2007-0475",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32171",
          "name" : "photogalerie-view-sql-injection(32171)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3261",
          "name" : "3261",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:noname_media:photo_galerie_standard:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:noname_media:photo_galerie_standard:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0787",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "simple_invoices",
            "product" : {
              "product_data" : [ {
                "product_name" : "simple_invoices",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007-02-02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/31796",
          "name" : "31796",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24040",
          "name" : "24040",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22389",
          "name" : "22389",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.simpleinvoices.org/index.php?news=25",
          "name" : "http://www.simpleinvoices.org/index.php?news=25",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0481",
          "name" : "ADV-2007-0481",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32207",
          "name" : "simpleinvoices-controller-file-include(32207)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in controller.php in Simple Invoices before 20070202 allows remote attackers to execute arbitrary PHP code via a URL in the (1) module or (2) view parameter.  NOTE: some of these details are obtained from third party information."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that \"register_globals\" is enabled and \"magic_quotes_gpc\" is disabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:simple_invoices:simple_invoices:2007-02-02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0788",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mediawiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "mediawiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.wikimedia.org/pipermail/mediawiki-announce/2007-February/000059.html",
          "name" : "[MediaWiki-announce] 20070204 MediaWiki 1.9.2 released",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33091",
          "name" : "33091",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24039",
          "name" : "24039",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_2/phase3/RELEASE-NOTES",
          "name" : "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_2/phase3/RELEASE-NOTES",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22397",
          "name" : "22397",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0490",
          "name" : "ADV-2007-0490",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32217",
          "name" : "mediawiki-sortabletable-xss(32217)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in MediaWiki 1.9.x before 1.9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to \"sortable tables JavaScript.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.9.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.9.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0789",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "mambo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://mamboxchange.com/frs/shownotes.php?release_id=6232",
          "name" : "http://mamboxchange.com/frs/shownotes.php?release_id=6232",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33088",
          "name" : "33088",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24044",
          "name" : "24044",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0480",
          "name" : "ADV-2007-0480",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Mambo before 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in cancel edit functions, possibly related to the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.5.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2011-08-05T04:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0790",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "smartftp",
            "product" : {
              "product_data" : [ {
                "product_name" : "smartftp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.1002",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33086",
          "name" : "33086",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24051",
          "name" : "24051",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22390",
          "name" : "22390",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32214",
          "name" : "smartftp-banner-bo(32214)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3277",
          "name" : "3277",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smartftp:smartftp:2.0.1002:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0791",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "bugzilla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.20.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.20.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.20.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.21.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.21.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.22.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.23.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.23.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33090",
          "name" : "33090",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24031",
          "name" : "24031",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2222",
          "name" : "2222",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017585",
          "name" : "1017585",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.bugzilla.org/security/2.20.3/",
          "name" : "http://www.bugzilla.org/security/2.20.3/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459025/100/0/threaded",
          "name" : "20070203 Security Advisory for Bugzilla 2.20.3, 2.22.1, and 2.23.3",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22380",
          "name" : "22380",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0477",
          "name" : "ADV-2007-0477",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32248",
          "name" : "bugzilla-atom-feed-xss(32248)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and earlier versions down to 2.20.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.20.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.20.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.20.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.21.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.21.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.22:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.22.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.23.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.23.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0792",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "bugzilla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.23.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35862",
          "name" : "35862",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2222",
          "name" : "2222",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017585",
          "name" : "1017585",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.bugzilla.org/security/2.20.3/",
          "name" : "http://www.bugzilla.org/security/2.20.3/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459025/100/0/threaded",
          "name" : "20070203 Security Advisory for Bugzilla 2.20.3, 2.22.1, and 2.23.3",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22380",
          "name" : "22380",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0477",
          "name" : "ADV-2007-0477",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32252",
          "name" : "bugzilla-htaccess-information-disclosure(32252)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.23.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0793",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "globalmegacorp",
            "product" : {
              "product_data" : [ {
                "product_name" : "dvddb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33679",
          "name" : "33679",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2221",
          "name" : "2221",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459149/100/0/threaded",
          "name" : "20070204 dvddb-0.6 media remote file include vuln.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:globalmegacorp:dvddb:0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0794",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "globalmegacorp",
            "product" : {
              "product_data" : [ {
                "product_name" : "dvddb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33670",
          "name" : "33670",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459151/100/0/threaded",
          "name" : "20070204 dvddb-0.6 media sql-inj. vuln.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459180/100/0/threaded",
          "name" : "20070205 Re: dvddb-0.6 media sql-inj. vuln.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/481327/100/100/threaded",
          "name" : "20071002 Re: dvddb-0.6 media sql-inj. vuln.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  SQL injection vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary SQL commands via the user parameter.  NOTE: this issue has been disputed by a reliable third party, who states that inc/common.php only contains function definitions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:globalmegacorp:dvddb:0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0795",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wap",
            "product" : {
              "product_data" : [ {
                "product_name" : "wap_portal_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.x",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33671",
          "name" : "33671",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33672",
          "name" : "33672",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35770",
          "name" : "35770",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2216",
          "name" : "2216",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459147/100/0/threaded",
          "name" : "20070203 Wap Portal Serve 1.* <= Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32196",
          "name" : "wapportal-index-file-include(32196)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wap:wap_portal_server:1.x:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0796",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bluecoat",
            "product" : {
              "product_data" : [ {
                "product_name" : "winproxy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=471",
          "name" : "20070202 Blue Coat Systems WinProxy CONNECT Method Heap Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33097",
          "name" : "33097",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24049",
          "name" : "24049",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017586",
          "name" : "1017586",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22393",
          "name" : "22393",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0482",
          "name" : "ADV-2007-0482",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32204",
          "name" : "winproxy-connect-bo(32204)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Blue Coat Systems WinProxy 6.1a and 6.0 r1c, and possibly earlier, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long HTTP CONNECT request, which triggers heap corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bluecoat:winproxy:6.0:r1c:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bluecoat:winproxy:6.1:r1a:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0797",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bluevirus-design",
            "product" : {
              "product_data" : [ {
                "product_name" : "sma-db",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33096",
          "name" : "33096",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24035",
          "name" : "24035",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22391",
          "name" : "22391",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0494",
          "name" : "ADV-2007-0494",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32190",
          "name" : "smadb-settings-file-include(32190)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3268",
          "name" : "3268",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pfad_z parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bluevirus-design:sma-db:0.3.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0798",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uapplication",
            "product" : {
              "product_data" : [ {
                "product_name" : "ublog_reload",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33641",
          "name" : "33641",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33642",
          "name" : "33642",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33643",
          "name" : "33643",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33644",
          "name" : "33644",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackerscenter.com/archive/view.asp?id=27270",
          "name" : "http://www.hackerscenter.com/archive/view.asp?id=27270",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459027/100/0/threaded",
          "name" : "20070203 Ublog Reload Admin Panel Multiple HTML Injections",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22382",
          "name" : "22382",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32185",
          "name" : "ublog-login-xss(32185)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login.asp; and allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (2) badword.asp, (3) polls.asp, and (4) users.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uapplication:ublog_reload:1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0799",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uapplication",
            "product" : {
              "product_data" : [ {
                "product_name" : "ublog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "reload_1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33640",
          "name" : "33640",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.hackerscenter.com/archive/view.asp?id=27270",
          "name" : "http://www.hackerscenter.com/archive/view.asp?id=27270",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459027/100/0/threaded",
          "name" : "20070203 Ublog Reload Admin Panel Multiple HTML Injections",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22382",
          "name" : "22382",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32187",
          "name" : "ublog-badword-sql-injection(32187)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in badword.asp in Ublog Reload 1.0.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uapplication:ublog:reload_1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-06T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0800",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc",
          "name" : "20070202-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc",
          "name" : "20070301-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2713",
          "name" : "FEDORA-2007-281",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/cms/node/2728",
          "name" : "FEDORA-2007-293",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742",
          "name" : "HPSBUX02153",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052209.html",
          "name" : "20070205 Firefox + popup blocker + XMLHttpRequest + srand() = oops",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052211.html",
          "name" : "20070205 Re: Firefox + popup blocker + XMLHttpRequest + srand() = oops",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html",
          "name" : "SUSE-SA:2007:019",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0077.html",
          "name" : "RHSA-2007:0077",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24205",
          "name" : "24205",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24238",
          "name" : "24238",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24287",
          "name" : "24287",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24290",
          "name" : "24290",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24293",
          "name" : "24293",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24320",
          "name" : "24320",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24328",
          "name" : "24328",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24333",
          "name" : "24333",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24342",
          "name" : "24342",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24343",
          "name" : "24343",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24384",
          "name" : "24384",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24393",
          "name" : "24393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24395",
          "name" : "24395",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24437",
          "name" : "24437",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24457",
          "name" : "24457",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24650",
          "name" : "24650",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-04.xml",
          "name" : "GLSA-200703-04",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131",
          "name" : "SSA:2007-066-05",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml",
          "name" : "GLSA-200703-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:050",
          "name" : "MDKSA-2007:050",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2007/mfsa2007-05.html",
          "name" : "http://www.mozilla.org/security/announce/2007/mfsa2007-05.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_22_mozilla.html",
          "name" : "SUSE-SA:2007:022",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32108",
          "name" : "32108",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0078.html",
          "name" : "RHSA-2007:0078",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0079.html",
          "name" : "RHSA-2007:0079",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0097.html",
          "name" : "RHSA-2007:0097",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0108.html",
          "name" : "RHSA-2007:0108",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459162/100/0/threaded",
          "name" : "20070205 Firefox + popup blocker + XMLHttpRequest + srand() = oops",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459163/100/0/threaded",
          "name" : "20070205 Re: [Full-disclosure] Firefox + popup blocker + XMLHttpRequest + srand() = oops",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461336/100/0/threaded",
          "name" : "20070226 rPSA-2007-0040-1 firefox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461809/100/0/threaded",
          "name" : "20070303 rPSA-2007-0040-3 firefox thunderbird",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22396",
          "name" : "22396",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22694",
          "name" : "22694",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017702",
          "name" : "1017702",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-428-1",
          "name" : "USN-428-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0718",
          "name" : "ADV-2007-0718",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0083",
          "name" : "ADV-2008-0083",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32194",
          "name" : "firefox-popup-security-bypass(32194)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1081",
          "name" : "https://issues.rpath.com/browse/RPL-1081",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1103",
          "name" : "https://issues.rpath.com/browse/RPL-1103",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10654",
          "name" : "oval:org.mitre.oval:def:10654",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-zone vulnerability in Mozilla Firefox 1.5.0.9 considers blocked popups to have an internal zone origin, which allows user-assisted remote attackers to cross zone restrictions and read arbitrary file:// URIs by convincing a user to show a blocked popup."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0801",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24393",
          "name" : "24393",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24437",
          "name" : "24437",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-04.xml",
          "name" : "GLSA-200703-04",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml",
          "name" : "GLSA-200703-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32108",
          "name" : "32108",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459162/100/0/threaded",
          "name" : "20070205 Firefox + popup blocker + XMLHttpRequest + srand() = oops",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459163/100/0/threaded",
          "name" : "20070205 Re: [Full-disclosure] Firefox + popup blocker + XMLHttpRequest + srand() = oops",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22396",
          "name" : "22396",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files with predictable filenames based on creation time, which allows remote attackers to execute arbitrary web script or HTML via a crafted XMLHttpRequest."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0802",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opera_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "opera",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0516.html",
          "name" : "20070418 Firefox 2.0.0.3 Phishing Protection Bypass Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.php",
          "name" : "http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33705",
          "name" : "33705",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459265/100/0/threaded",
          "name" : "20070206 Firefox 2.0.0.1 and Opera 9.10 Anty Fraud/Phishing Protection bypass.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=367538",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=367538",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the \".\" and \"/\" characters, which is not caught by the Phishing List blacklist filter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:opera_software:opera:9.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0803",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "stlport",
            "product" : {
              "product_data" : [ {
                "product_name" : "stlport",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33106",
          "name" : "33106",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33107",
          "name" : "33107",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24024",
          "name" : "24024",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24428",
          "name" : "24428",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-07.xml",
          "name" : "GLSA-200703-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=483468",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=483468",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22423",
          "name" : "22423",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0498",
          "name" : "ADV-2007-0498",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32242",
          "name" : "stlport-printed-floats-bo(32242)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32244",
          "name" : "stlport-rope-constructors-bo(32244)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in STLport before 5.0.3 allow remote attackers to execute arbitrary code via unspecified vectors relating to (1) \"print floats\" and (2) a missing null termination in the \"rope constructor.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stlport:stlport:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stlport:stlport:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stlport:stlport:5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0804",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ggcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "ggcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0_rc1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35849",
          "name" : "35849",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22412",
          "name" : "22412",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0492",
          "name" : "ADV-2007-0492",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32211",
          "name" : "ggcms-subpages-code-execution(32211)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3271",
          "name" : "3271",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via \"..\" sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ggcms:ggcms:1.1.0_rc1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0805",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "tru64",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00817515",
          "name" : "HPSBTU02179",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052227.html",
          "name" : "20070206 PS Information Leak on HP True64 Alpha OSF1 v5.1 1885",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33113",
          "name" : "33113",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://rawlab.mindcreations.com/codes/exp/nix/osf1tru64ps.ksh",
          "name" : "http://rawlab.mindcreations.com/codes/exp/nix/osf1tru64ps.ksh",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/24041",
          "name" : "24041",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25135",
          "name" : "25135",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017592",
          "name" : "1017592",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459266/100/0/threaded",
          "name" : "20070206 Re: [Full-disclosure] PS Information Leak on HP Tru64 Alpha OSF1v5.1 1885",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459275/100/0/threaded",
          "name" : "20070206 PS Information Leak on HP True64 Alpha OSF1 v5.1 1885",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459593/100/200/threaded",
          "name" : "20070207 Re: PS Information Leak on HP True64 Alpha OSF1 v5.1 1885",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018005",
          "name" : "1018005",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1654",
          "name" : "ADV-2007-1654",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32276",
          "name" : "tru64-ps-information-disclosure(32276)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including environment variables of arbitrary processes, via the \"auxewww\" argument, a similar issue to CVE-1999-1587."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:tru64:5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0806",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "les_news",
            "product" : {
              "product_data" : [ {
                "product_name" : "les_news",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2622",
          "name" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2622",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33686",
          "name" : "33686",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2226",
          "name" : "2226",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459186/100/0/threaded",
          "name" : "20070204 Les News v2.2 [Admin news without password]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Les News 2.2 allows remote attackers to bypass authentication and gain administrative access via a direct request for adminews/index_fr.php3, and possibly the adminews index documents for other localizations."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:les_news:les_news:2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0807",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "darrens_5-dollar_script_archive",
            "product" : {
              "product_data" : [ {
                "product_name" : "flashchat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24071",
          "name" : "24071",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2228",
          "name" : "2228",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459160/100/0/threaded",
          "name" : "20070205 flashChat 4.7.8 Cross Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22411",
          "name" : "22411",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0495",
          "name" : "ADV-2007-0495",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32208",
          "name" : "flashchat-info-xss(32208)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in info.php in flashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via a channel title (aka room name) that is not properly handled by the \"who's online\" feature."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:darrens_5-dollar_script_archive:flashchat:4.7.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0808",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mina_ajans",
            "product" : {
              "product_data" : [ {
                "product_name" : "mina_ajans_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33687",
          "name" : "33687",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459191/100/0/threaded",
          "name" : "20070205 Mina Ajans Script Remote File Inclusion Vuln.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32243",
          "name" : "mina-multiple-file-include(32243)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in Mina Ajans Script allows remote attackers to execute arbitrary PHP code via a URL in the syf parameter to an unspecified PHP script."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mina_ajans:mina_ajans_script:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0809",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ptirhiikmods",
            "product" : {
              "product_data" : [ {
                "product_name" : "mod-ch",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2007-February/001285.html",
          "name" : "20070207 true: Categories hierarchy class_template.php RFI",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33722",
          "name" : "33722",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22400",
          "name" : "22400",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0493",
          "name" : "ADV-2007-0493",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32193",
          "name" : "ch-classtemplate-file-include(32193)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3270",
          "name" : "3270",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2 in ptirhiikmods allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ptirhiikmods:mod-ch:2.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0810",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "geeklog",
            "product" : {
              "product_data" : [ {
                "product_name" : "geeklog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35749",
          "name" : "35749",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22386",
          "name" : "22386",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32205",
          "name" : "geeklog-baseview-file-include(32205)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3267",
          "name" : "3267",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_libraries] parameter.  NOTE: this might be a vulnerability in MVCnPHP rather than a vulnerability in GeekLog."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geeklog:geeklog:2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0811",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/37636",
          "name" : "37636",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.powerhacker.net/exploit/IE_NULL_CRASH.html",
          "name" : "http://www.powerhacker.net/exploit/IE_NULL_CRASH.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22408",
          "name" : "22408",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3272",
          "name" : "3272",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:*:windows_2000:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:sp2:windows_xp:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0812",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "woltlab",
            "product" : {
              "product_data" : [ {
                "product_name" : "burning_board_lite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2_pl3e",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32034",
          "name" : "32034",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24027",
          "name" : "24027",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22415",
          "name" : "22415",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0491",
          "name" : "ADV-2007-0491",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32172",
          "name" : "wbblite-pms-sql-injection(32172)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3262",
          "name" : "3262",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to execute arbitrary SQL commands via the pmid[0] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board_lite:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board_lite:1.0.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board_lite:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board_lite:1.0.2_pl3e:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0813",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "home_production",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysearchengine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2621",
          "name" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2621",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33653",
          "name" : "33653",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459145/100/0/threaded",
          "name" : "20070204 MysearchEngine XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22402",
          "name" : "22402",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32201",
          "name" : "mysearchengine-search-xss(32201)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Home production MySearchEngine allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:home_production:mysearchengine:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0814",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adrenalin_labs",
            "product" : {
              "product_data" : [ {
                "product_name" : "adrenalins_asp_chat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2620",
          "name" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2620",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33654",
          "name" : "33654",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2233",
          "name" : "2233",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459144/100/0/threaded",
          "name" : "20070203 Adrenalin's ASP Chat XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22392",
          "name" : "22392",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32203",
          "name" : "adrenalin-unspecified-script-xss(32203)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Adrenalin's ASP Chat allow remote attackers to inject arbitrary web script or HTML (1) via the psuedo (pseudo) field or (2) during chat."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adrenalin_labs:adrenalins_asp_chat:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0815",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uapplication",
            "product" : {
              "product_data" : [ {
                "product_name" : "uphotogallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33243",
          "name" : "33243",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2227",
          "name" : "2227",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459187/100/0/threaded",
          "name" : "20070204 Uphotogallery Multiple Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22404",
          "name" : "22404",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32229",
          "name" : "uphotogallery-imagesarchive-xss(32229)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in images_archive.asp in Uapplication Uphotogallery 1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the s parameter.  NOTE: the thumbnails.asp vector is already covered by CVE-2006-3023."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uapplication:uphotogallery:1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0816",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ca",
            "product" : {
              "product_data" : [ {
                "product_name" : "brightstor_arcserve_backup",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32989",
          "name" : "32989",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24009",
          "name" : "24009",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24512",
          "name" : "24512",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp",
          "name" : "http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22365",
          "name" : "22365",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0461",
          "name" : "ADV-2007-0461",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317",
          "name" : "http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35058",
          "name" : "http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35058",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32137",
          "name" : "brightstor-catirpc-dos(32137)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3248",
          "name" : "3248",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to cause a denial of service (service crash) via a crafted TADDR2UADDR that triggers a null pointer dereference in catirpc.dll, possibly related to null credentials or verifier fields."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup:11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup:11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup:11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup:11.5:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup:11.5:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0817",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "coldfusion",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32120",
          "name" : "32120",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24115",
          "name" : "24115",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/security/bulletins/apsb07-04.html",
          "name" : "http://www.adobe.com/support/security/bulletins/apsb07-04.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459178/100/0/threaded",
          "name" : "20070205 Cold Fusion Web Server XSS 0 day",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22401",
          "name" : "22401",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017645",
          "name" : "1017645",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0593",
          "name" : "ADV-2007-0593",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:coldfusion:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:coldfusion:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:coldfusion:7.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0818",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-0396.  Reason: This candidate is a duplicate of CVE-2007-0396.  Notes: All CVE users should reference CVE-2007-0396 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        }, {
          "lang" : "en",
          "value" : "The configuration has conditions of \"IPFilter with PHNE_34474 applied\" must be set, so a medium difficulty."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2007-02-07T11:28Z",
    "lastModifiedDate" : "2008-09-11T00:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0819",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "network_node_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0174.html",
          "name" : "20070208 SecurityVulns.com: HP Network Node Manager remote console weak files permissions",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=125063027228539&w=2",
          "name" : "HPSBMA02448",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33130",
          "name" : "33130",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24066",
          "name" : "24066",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017609",
          "name" : "1017609",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.com/news/HP/NNM/RC/WP.html",
          "name" : "http://securityvulns.com/news/HP/NNM/RC/WP.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22475",
          "name" : "22475",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0533",
          "name" : "ADV-2007-0533",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32362",
          "name" : "openview-nnm-directory-privilege-escalation(32362)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "HP Network Node Manager (NNM) Remote Console 7.50, 7.51, and 7.53 assigns Everyone Full Control permission for the %PROGRAMFILES%\\HP OpenView directory tree, which allows local users to gain privileges via a Trojan horse executable file or ActiveX component, or a modified bin\\ovtrcsvc.exe for the HP Open View Shared Trace Service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:network_node_manager:7.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0820",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cedric",
            "product" : {
              "product_data" : [ {
                "product_name" : "claire_portailphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35756",
          "name" : "35756",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35757",
          "name" : "35757",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35758",
          "name" : "35758",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22381",
          "name" : "22381",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/28867",
          "name" : "28867",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42123",
          "name" : "portailphp-index-file-include(42123)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the chemin parameter to (1) mod_news/index.php, (2) mod_news/goodies.php, or (3) mod_search/index.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cedric:claire_portailphp:2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T20:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0821",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cedric",
            "product" : {
              "product_data" : [ {
                "product_name" : "claire_portailphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35850",
          "name" : "35850",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35851",
          "name" : "35851",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22381",
          "name" : "22381",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter to (1) mod_news/index.php or (2) mod_news/goodies.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cedric:claire_portailphp:2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T20:28Z",
    "lastModifiedDate" : "2008-11-15T06:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0822",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0012.html",
          "name" : "20070201 umount crash and xterm (kind of) information leak!",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://gotfault.wordpress.com/2007/01/18/umount-bug/",
          "name" : "http://gotfault.wordpress.com/2007/01/18/umount-bug/",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33652",
          "name" : "33652",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:053",
          "name" : "MDKSA-2007:053",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22850",
          "name" : "22850",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017729",
          "name" : "1017729",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allows local users to trigger a NULL dereference and application crash by invoking the program with a pathname for a USB pen drive that was mounted and then physically removed, which might allow the users to obtain sensitive information, including core file contents."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T20:28Z",
    "lastModifiedDate" : "2010-09-15T05:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0823",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "slackware",
            "product" : {
              "product_data" : [ {
                "product_name" : "slackware_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0012.html",
          "name" : "20070201 umount crash and xterm (kind of) information leak!",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://gotfault.wordpress.com/2007/02/01/a-funny-case/",
          "name" : "http://gotfault.wordpress.com/2007/02/01/a-funny-case/",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33651",
          "name" : "33651",
          "refsource" : "OSVDB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users' files, or obtain other sensitive information, by reading the xterm process memory.  NOTE: it could be argued that this is an expected consequence of multiple users sharing the same interactive process, in which case this is not a vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:slackware:slackware_linux:10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T20:28Z",
    "lastModifiedDate" : "2008-11-15T06:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0824",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lightro",
            "product" : {
              "product_data" : [ {
                "product_name" : "lightro_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34599",
          "name" : "34599",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22430",
          "name" : "22430",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0511",
          "name" : "ADV-2007-0511",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32270",
          "name" : "lightro-inhalt-file-include(32270)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3275",
          "name" : "3275",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dateien[news] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lightro:lightro_cms:1_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T22:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0825",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "flashfxp",
            "product" : {
              "product_data" : [ {
                "product_name" : "flashfxp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.4.0_build_1145",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35796",
          "name" : "35796",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22433",
          "name" : "22433",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32416",
          "name" : "flashfxp-pwdcommand-dos(32416)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3276",
          "name" : "3276",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that contains a long string with deeply nested directory structure, possibly due to a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:flashfxp:flashfxp:3.4.0_build_1145:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T22:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0826",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kisisel_site_2007",
            "product" : {
              "product_data" : [ {
                "product_name" : "kisisel_site_forum.asp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35831",
          "name" : "35831",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22435",
          "name" : "22435",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0510",
          "name" : "ADV-2007-0510",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32422",
          "name" : "kisisel-forum-sql-injection(32422)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3278",
          "name" : "3278",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands via the forumid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kisisel_site_2007:kisisel_site_forum.asp:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T22:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0827",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alibaba",
            "product" : {
              "product_data" : [ {
                "product_name" : "alipay_activex_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.2.471",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052250.html",
          "name" : "20070207 Alibaba Alipay Remote Code Execute Vulnerability-0DAY",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33123",
          "name" : "33123",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24063",
          "name" : "24063",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22446",
          "name" : "22446",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0520",
          "name" : "ADV-2007-0520",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32367",
          "name" : "alipay-activex-code-execution(32367)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3279",
          "name" : "3279",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the Remove method with an invalid index argument, which is used as an offset for a function call."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alibaba:alipay_activex_control:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.4.2.471"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-07T22:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0828",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mysqlnewsengine",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysqlnewsengine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33678",
          "name" : "33678",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2229",
          "name" : "2229",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459290/100/0/threaded",
          "name" : "20070206 MySQLNewsEngine (affichearticles.php3) Remote File Inc. Vuln.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22431",
          "name" : "22431",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0513",
          "name" : "ADV-2007-0513",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32266",
          "name" : "mysqlnewsengine-affichearticle-file-include(32266)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in affichearticles.php3 in MySQLNewsEngine allows remote attackers to execute arbitrary PHP code via a URL in the newsenginedir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysqlnewsengine:mysqlnewsengine:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0829",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alwil",
            "product" : {
              "product_data" : [ {
                "product_name" : "avast_antivirus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6.460",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.489",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.566",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.660",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.676",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33114",
          "name" : "33114",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24068",
          "name" : "24068",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.avast.com/eng/avast-4-server-revision-history.html",
          "name" : "http://www.avast.com/eng/avast-4-server-revision-history.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22425",
          "name" : "22425",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0499",
          "name" : "ADV-2007-0499",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32269",
          "name" : "avast-password-security-bypass(32269)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "avast! Server Edition before 4.7.726 does not demand a password in a certain intended context, even when a password has been set, which allows local users to bypass authentication requirements."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alwil:avast_antivirus:4.6.460:*:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alwil:avast_antivirus:4.6.489:*:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alwil:avast_antivirus:4.6.566:*:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alwil:avast_antivirus:4.7.660:*:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alwil:avast_antivirus:4.7.676:*:server:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T22:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0830",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jelsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "vbulletin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.6.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35152",
          "name" : "35152",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24085",
          "name" : "24085",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459289/100/0/threaded",
          "name" : "20070206 VBulletin AdminCP Index.PHP Multiple Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459367/100/0/threaded",
          "name" : "20070207 Re: VBulletin AdminCP Index.PHP Multiple Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32268",
          "name" : "vbulletin-admincp-index-xss(32268)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Multiple cross-site scripting (XSS) vulnerabilities in the Admin Control Panel (AdminCP) in Jelsoft vBulletin 3.6.4 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors related to the (1) User Group Manager, (2) User Rank Manager, (3) User Title Manager, (4) BB Code Manager, (5) Attachment Manager, (6) Calendar Manager, and (7) Forums & Moderators functions.  NOTE: the vendor disputes this issue, stating that modifying HTML is an intended privilege of an administrator.  NOTE: it is possible that this issue overlaps CVE-2006-6040."
        }, {
          "lang" : "en",
          "value" : "Vendor has stated that remotely authenticated administrators were given the ability to inject arbitrary HTML/webscript code by design."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jelsoft:vbulletin:3.6.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-07T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0831",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "atsphp",
            "product" : {
              "product_data" : [ {
                "product_name" : "atsphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/458581/100/100/threaded",
          "name" : "20070130 Atsphp 5.0.1 [Top Sites] [index.php] - Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458600/100/0/threaded",
          "name" : "20070130 Re: BOGUS: Atsphp 5.0.1 [Top Sites] [index.php] - Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Atsphp 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the CONF[path] parameter to (1) index.php, (2) sources/usercp.php, or (3) sources/admin.php.  NOTE: Another researcher has disputed this vulnerability, noting that CONF[path] is defined before use in index.php, that CONF[path] inclusion cannot occur through a direct request to other affected files, and that usercp.php is a typo of user_cp.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atsphp:atsphp:5.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0832",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vmware",
            "product" : {
              "product_data" : [ {
                "product_name" : "workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.3_build_34685",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33222",
          "name" : "33222",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459140/100/0/threaded",
          "name" : "20070203 Vmare workstation guest isolation weaknesses (clipboard transfer)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22413",
          "name" : "22413",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the \"Enable copy and paste to and from this virtual machine\" checkbox is changed, which allows local users to obtain sensitive information or conduct certain attacks that are facilitated by weaker isolation between the host and guest operating systems."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.3_build_34685:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.2
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0833",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vmware",
            "product" : {
              "product_data" : [ {
                "product_name" : "workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.3_build_34685",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33221",
          "name" : "33221",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459140/100/0/threaded",
          "name" : "20070203 Vmare workstation guest isolation weaknesses (clipboard transfer)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22413",
          "name" : "22413",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "VMware Workstation 5.5.3 34685, when the \"Enable copy and paste to and from this virtual machine\" option is enabled, preserves clipboard data on the guest operating system after it was deleted on the host operating system, which might allow local users to read clipboard contents by moving the focus back to the host operating system."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vmware:workstation:5.5.3_build_34685:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.2
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T22:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0834",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "darrens_5-dollar_script_archive",
            "product" : {
              "product_data" : [ {
                "product_name" : "flashchat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35797",
          "name" : "35797",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24071",
          "name" : "24071",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32417",
          "name" : "flashchat-username-xss(32417)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in FlashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via the user name field when the user joins a chat room, a different vulnerability than CVE-2007-0807.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:darrens_5-dollar_script_archive:flashchat:4.7.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-07T23:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0835",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "coppermine",
            "product" : {
              "product_data" : [ {
                "product_name" : "coppermine_photo_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33093",
          "name" : "33093",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24019",
          "name" : "24019",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22406",
          "name" : "22406",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32236",
          "name" : "coppermine-admin-command-execution(32236)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to execute arbitrary shell commands via shell metacharacters (\";\" semicolon) in the \"Command line options for ImageMagick\" form field, when used as an option to ImageMagick's convert command.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0836",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "coppermine",
            "product" : {
              "product_data" : [ {
                "product_name" : "coppermine_photo_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33094",
          "name" : "33094",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24019",
          "name" : "24019",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22409",
          "name" : "22409",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32233",
          "name" : "coppermine-admin-file-include(32233)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote files via the (1) \"Path to custom header include\" and (2) \"Path to custom footer include\" form fields.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0837",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "agermenu",
            "product" : {
              "product_data" : [ {
                "product_name" : "agermenu",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.03",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33681",
          "name" : "33681",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001288.html",
          "name" : "20070207 true: agermenu",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001297.html",
          "name" : "20070207 false: Agermenu 0.03",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22442",
          "name" : "22442",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0512",
          "name" : "ADV-2007-0512",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32283",
          "name" : "agermenu-topinc-file-include(32283)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3280",
          "name" : "3280",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:agermenu:agermenu:0.03:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0838",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freeproxy",
            "product" : {
              "product_data" : [ {
                "product_name" : "freeproxy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.92",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=117086856902907&w=2",
          "name" : "20070206 Medium level security hole in FreeProxy",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://marc.info/?l=full-disclosure&m=117085666921871&w=2",
          "name" : "20070206 Medium level security hole in FreeProxy",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://osvdb.org/33116",
          "name" : "33116",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/24064",
          "name" : "24064",
          "refsource" : "SECUNIA",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "http://www.handcraftedsoftware.org/index.php?page=3&mode=article&k=60",
          "name" : "http://www.handcraftedsoftware.org/index.php?page=3&mode=article&k=60",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22445",
          "name" : "22445",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0514",
          "name" : "ADV-2007-0514",
          "refsource" : "VUPEN",
          "tags" : [ "Not Applicable" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32303",
          "name" : "freeproxy-hostname-portnumber-dos(32303)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "FreeProxy before 3.92 Build 1626 allows malicious users to cause a denial of service (infinite loop) via a HOST: header with a hostname and port number that refers to the server itself."
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/835.html\">CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeproxy:freeproxy:3.92:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T00:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0839",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "valarsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "webmatic",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33126",
          "name" : "33126",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24092",
          "name" : "24092",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001292.html",
          "name" : "20070207 true: WebMatic 2.6 RFI",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22444",
          "name" : "22444",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0534",
          "name" : "ADV-2007-0534",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32318",
          "name" : "webmatic-indexalbum-file-include(32318)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3281",
          "name" : "3281",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) P_LIB and (2) P_INDEX parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:valarsoft:webmatic:2.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T00:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0840",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hlstats",
            "product" : {
              "product_data" : [ {
                "product_name" : "hlstats",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.34",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33099",
          "name" : "33099",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24062",
          "name" : "24062",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=484226",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=484226",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22422",
          "name" : "22422",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in HLstats before 1.35 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the search class.  NOTE: it is possible that this issue overlaps CVE-2006-4543.3 or CVE-2006-4454."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hlstats:hlstats:1.34:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-08T02:28Z",
    "lastModifiedDate" : "2008-11-15T06:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0841",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vbdrupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "vbdrupal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7.5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35848",
          "name" : "35848",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23990",
          "name" : "23990",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vbdrupal.org/forum/showthread.php?t=786",
          "name" : "http://www.vbdrupal.org/forum/showthread.php?t=786",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0415",
          "name" : "ADV-2007-0415",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in vbDrupal before 4.7.6.0 have unknown impact and remote attack vectors.  NOTE: the vector related to Drupal is covered by CVE-2007-0626.  These vulnerabilities might be associated with other CVE identifiers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vbdrupal:vbdrupal:4.7.5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T02:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0842",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "visual_c++",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "visual_studio",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://msdn2.microsoft.com/en-us/library/a442x3ye(VS.80).aspx",
          "name" : "http://msdn2.microsoft.com/en-us/library/a442x3ye(VS.80).aspx",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33626",
          "name" : "33626",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2237",
          "name" : "2237",
          "refsource" : "SREASON",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459847/100/0/threaded",
          "name" : "20070212 SecurityVulns.com: Microsoft Visual C++ 8.0 standard library time functions invalid assertion DoS (Problem 3000).",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32454",
          "name" : "visualstudio-time-dos(32454)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions.  However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visual_c\\+\\+:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visual_studio:2005:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0843",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052613.html",
          "name" : "20070222 Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33474",
          "name" : "33474",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24245",
          "name" : "24245",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2282",
          "name" : "2282",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityvulns.com/advisories/readdirectorychanges.asp",
          "name" : "http://securityvulns.com/advisories/readdirectorychanges.asp",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460887/100/0/threaded",
          "name" : "20070222 Re[2]: [Full-disclosure] Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460899/100/0/threaded",
          "name" : "20070222 Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22664",
          "name" : "22664",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0701",
          "name" : "ADV-2007-0701",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32644",
          "name" : "win-readdirectory-information-disclosure(32644)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:64-bit_2003:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:embedded:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-23T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0844",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pam_ssh",
            "product" : {
              "product_data" : [ {
                "product_name" : "pam_ssh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.91",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33119",
          "name" : "33119",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24061",
          "name" : "24061",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=484376",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=484376",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22461",
          "name" : "22461",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0524",
          "name" : "ADV-2007-0524",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pam_ssh:pam_ssh:1.91:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T17:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0845",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "advanced_poll",
            "product" : {
              "product_data" : [ {
                "product_name" : "advanced_poll",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35847",
          "name" : "35847",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22451",
          "name" : "22451",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32337",
          "name" : "advancedpoll-uid-authentication-bypass(32337)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3282",
          "name" : "3282",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain administrator privileges by obtaining a valid session identifier and setting the uid parameter to 1."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:advanced_poll:advanced_poll:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:advanced_poll:advanced_poll:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:advanced_poll:advanced_poll:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:advanced_poll:advanced_poll:2.0.5:*:dev:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0846",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "open_tibia_server_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "open_tibia_server_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33170",
          "name" : "33170",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24116",
          "name" : "24116",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22450",
          "name" : "22450",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32324",
          "name" : "otscms-forum-xss(32324)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3283",
          "name" : "3283",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to inject arbitrary HTML or web script via the name parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_tibia_server_cms:open_tibia_server_cms:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_tibia_server_cms:open_tibia_server_cms:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_tibia_server_cms:open_tibia_server_cms:2.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_tibia_server_cms:open_tibia_server_cms:2.1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0847",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "open_tibia_server_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "open_tibia_server_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33169",
          "name" : "33169",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24116",
          "name" : "24116",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22450",
          "name" : "22450",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32322",
          "name" : "otscms-priv-sql-injection(32322)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3283",
          "name" : "3283",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to priv.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_tibia_server_cms:open_tibia_server_cms:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_tibia_server_cms:open_tibia_server_cms:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_tibia_server_cms:open_tibia_server_cms:2.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open_tibia_server_cms:open_tibia_server_cms:2.1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0848",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "maian_recipe",
            "product" : {
              "product_data" : [ {
                "product_name" : "maian_recipe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33125",
          "name" : "33125",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33689",
          "name" : "33689",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24074",
          "name" : "24074",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-February/001299.html",
          "name" : "20070207 true: Agermenu 0.03",
          "refsource" : "VIM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0537",
          "name" : "ADV-2007-0537",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32346",
          "name" : "maianrecipe-classmail-file-include(32346)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3284",
          "name" : "3284",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maian_recipe:maian_recipe:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0849",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "syscp_team",
            "product" : {
              "product_data" : [ {
                "product_name" : "syscp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.15",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33128",
          "name" : "33128",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24102",
          "name" : "24102",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459397/100/0/threaded",
          "name" : "20070207 Ability to inject and execute any code as root in SysCP",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22453",
          "name" : "22453",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP",
          "name" : "http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "scripts/cronscript.php in SysCP 1.2.15 and earlier does not properly quote pathnames in user home directories, which allows local users to gain privileges by placing shell metacharacters in a directory name, and then using the control panel to protect this directory, a different vulnerability than CVE-2005-2568."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:syscp_team:syscp:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.15"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0850",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "syscp_team",
            "product" : {
              "product_data" : [ {
                "product_name" : "syscp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33127",
          "name" : "33127",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24102",
          "name" : "24102",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459397/100/0/threaded",
          "name" : "20070207 Ability to inject and execute any code as root in SysCP",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22454",
          "name" : "22454",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP",
          "name" : "http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32330",
          "name" : "syscp-cronscript-code-execution(32330)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:syscp_team:syscp:1.2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:syscp_team:syscp:1.2.15:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0851",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trend_micro",
            "product" : {
              "product_data" : [ {
                "product_name" : "client-server-messaging_suite_smb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "gold",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "client-server_suite_smb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "gold",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "control_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "gold",
                    "version_affected" : "="
                  }, {
                    "version_value" : "netware",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interscan_emanager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.51_j",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interscan_messaging_security_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.81",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5_build_1183",
                    "version_affected" : "="
                  }, {
                    "version_value" : "gold",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interscan_viruswall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.0_build1166",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.0_build_1182",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.0_build1190",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8.0_build1130",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.81",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "gold",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interscan_viruswall_for_windows_nt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.52_build1466",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interscan_viruswall_scan_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.510.0-1002",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interscan_web_security_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "gold",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interscan_webmanager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interscan_webprotect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "gold",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "officescan",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "corporate_3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "corporate_3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "corporate_3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "corporate_3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "corporate_3.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "corporate_3.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "corporate_5.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "corporate_5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "corporate_5.58",
                    "version_affected" : "="
                  }, {
                    "version_value" : "corporate_6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "corporate_7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "corporate_7.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pc-cillin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pc-cillin_internet_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "14_14.00.1485",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005_12.0.0_0_build_1244",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006_14.10.0.1023",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pc_cillin_-_internet_security_2006",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "portalprotect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "scanmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.81",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "gold",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "scanmail_emanager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "scanning_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "serverprotect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.58",
                    "version_affected" : "="
                  }, {
                    "version_value" : "linux",
                    "version_affected" : "="
                  }, {
                    "version_value" : "linux_1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "novell_netware",
                    "version_affected" : "="
                  }, {
                    "version_value" : "windows",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "viruswall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "web_security_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "webprotect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034289",
          "name" : "http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034289",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://jvn.jp/jp/JVN%2377366274/index.html",
          "name" : "JVN#77366274",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=470",
          "name" : "20070208 Trend Micro AntiVirus UPX Parsing Kernel Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33038",
          "name" : "33038",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24087",
          "name" : "24087",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24128",
          "name" : "24128",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017601",
          "name" : "1017601",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017602",
          "name" : "1017602",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017603",
          "name" : "1017603",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.jpcert.or.jp/at/2007/at070004.txt",
          "name" : "http://www.jpcert.or.jp/at/2007/at070004.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/276432",
          "name" : "VU#276432",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22449",
          "name" : "22449",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0522",
          "name" : "ADV-2007-0522",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0569",
          "name" : "ADV-2007-0569",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32352",
          "name" : "antivirus-upx-bo(32352)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable."
        }, {
          "lang" : "en",
          "value" : "Failed exploit attempts will likely cause a denial-of-service condition."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:client-server-messaging_suite_smb:gold:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:client-server_suite_smb:gold:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:control_manager:2.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:control_manager:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:control_manager:gold:*:as_400:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:control_manager:gold:*:s_390:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:control_manager:gold:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:control_manager:gold:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:control_manager:gold:*:windows_nt:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:control_manager:netware:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_emanager:3.5:*:hp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_emanager:3.5.2:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_emanager:3.6:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_emanager:3.6:*:sun:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_emanager:3.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_emanager:3.51_j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_messaging_security_suite:*:*:linux_5.1.1:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_messaging_security_suite:3.81:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_messaging_security_suite:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_messaging_security_suite:5.5_build_1183:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_messaging_security_suite:gold:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_messaging_security_suite:gold:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_messaging_security_suite:gold:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.0.1:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.0.1:*:unix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.1.0:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.6:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.6:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.6:*:windows_nt:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.6.0_build1166:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.6.0_build_1182:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.6.5:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.7.0_build1190:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.8.0_build1130:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:3.81:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:5.1:*:windows_nt:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:gold:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:gold:*:linux_for_smb:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:gold:*:smb:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:gold:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall:gold:*:windows_nt_for_smb:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:3.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:3.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:3.52_build1466:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_viruswall_scan_engine:7.510.0-1002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_web_security_suite:*:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_web_security_suite:*:*:linux_1.0.0_ja:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_web_security_suite:gold:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_web_security_suite:gold:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_web_security_suite:gold:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_webmanager:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_webmanager:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_webmanager:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_webprotect:gold:*:isa:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:3.0:*:corporate:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:4.5.0:*:microsof_sbs:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_3.0:*:windows_nt_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_3.1.1:*:windows_nt_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_3.5:*:windows_nt_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_3.11:*:windows_nt_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_3.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_3.13:*:windows_nt_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_3.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_5.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_5.58:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:officescan:corporate_7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:pc-cillin:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:pc-cillin:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:pc-cillin:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:pc-cillin:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:pc-cillin:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:pc-cillin:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:pc-cillin_internet_security:14_14.00.1485:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:pc-cillin_internet_security:2005_12.0.0_0_build_1244:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:pc-cillin_internet_security:2006_14.10.0.1023:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:pc-cillin_internet_security:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:pc_cillin_-_internet_security_2006:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:portalprotect:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:portalprotect:1.2:*:sharepoint:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanmail:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanmail:2.6:*:domino:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanmail:2.51:*:domino:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanmail:3.8:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanmail:3.81:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanmail:6.1:*:microsoft_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanmail:gold:*:lotus_domino_on_aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanmail:gold:*:lotus_domino_on_as_400:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanmail:gold:*:lotus_domino_on_s_390:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanmail:gold:*:lotus_domino_on_solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanmail:gold:*:lotus_domino_on_windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanmail_emanager:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:scanning_engine:7.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.58:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.58:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:linux:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:linux_1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:novell_netware:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:windows:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:viruswall:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:web_security_suite:1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:webprotect:3.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0852",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "techexcel_inc.",
            "product" : {
              "product_data" : [ {
                "product_name" : "devtrack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33122",
          "name" : "33122",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23217",
          "name" : "23217",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22460",
          "name" : "22460",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in DevTrack 6.x allows remote attackers to inject arbitrary web script or HTML via the \"Keyword search\" form field and unspecified other form fields that populate a public saved query.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:techexcel_inc.:devtrack:6.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2008-11-15T06:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0853",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "techexcel_inc.",
            "product" : {
              "product_data" : [ {
                "product_name" : "devtrack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33121",
          "name" : "33121",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23217",
          "name" : "23217",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22460",
          "name" : "22460",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32348",
          "name" : "devtrack-username-sql-injection(32348)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in DevTrack 6.0.3 allows remote attackers to execute arbitrary SQL commands via the Username form field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:techexcel_inc.:devtrack:6.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0854",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cpanel",
            "product" : {
              "product_data" : [ {
                "product_name" : "webhost_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://changelog.cpanel.net/index.cgi",
          "name" : "http://changelog.cpanel.net/index.cgi",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32043",
          "name" : "32043",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33240",
          "name" : "33240",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/35750",
          "name" : "35750",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24097",
          "name" : "24097",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459409/100/0/threaded",
          "name" : "20070207 remote file include in whm (all version)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459449/100/0/threaded",
          "name" : "20070208 Re: remote file include in whm (all version)",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22455",
          "name" : "22455",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0545",
          "name" : "ADV-2007-0545",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32400",
          "name" : "cpanel-webhost-objcache-xss(32400)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Remote file inclusion vulnerability in scripts2/objcache in cPanel WebHost Manager (WHM) allows remote attackers to execute arbitrary code via a URL in the obj parameter.  NOTE: a third party claims that this issue is not file inclusion because the contents are not parsed, but the attack can be used to overwrite files in /var/cpanel/objcache or provide unexpected web page contents."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0855",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rarlab",
            "product" : {
              "product_data" : [ {
                "product_name" : "unrar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.61",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=472",
          "name" : "20070207 RARLabs Unrar Password Prompt Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33124",
          "name" : "33124",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24077",
          "name" : "24077",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24165",
          "name" : "24165",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200702-04.xml",
          "name" : "GLSA-200702-04",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017593",
          "name" : "1017593",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2007_5_sr.html",
          "name" : "SUSE-SR:2007:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22447",
          "name" : "22447",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0523",
          "name" : "ADV-2007-0523",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32357",
          "name" : "unrar-password-archive-bo(32357)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, password-protected archive."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rarlab:unrar:3.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rarlab:unrar:3.61:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0856",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trend_micro",
            "product" : {
              "product_data" : [ {
                "product_name" : "client-server-messaging_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "damage_cleanup_services",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pc-cillin_internet_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "tmcomm.sys",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.1052",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "trend_micro_antirootkit_common_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "trend_micro_antispyware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0_sp2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2_sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "trend_micro_antivirus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vsapini.sys",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.320.1003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034432&id=EN-1034432",
          "name" : "http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034432&id=EN-1034432",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=469",
          "name" : "20070207 Trend Micro TmComm Local Privilege Escalation Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33039",
          "name" : "33039",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24069",
          "name" : "24069",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017604",
          "name" : "1017604",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017605",
          "name" : "1017605",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017606",
          "name" : "1017606",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/282240",
          "name" : "VU#282240",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/666800",
          "name" : "VU#666800",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22448",
          "name" : "22448",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0521",
          "name" : "ADV-2007-0521",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32353",
          "name" : "trendmicro-tmcomm-privilege-escalation(32353)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\\\.\\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:client-server-messaging_security:3.5:*:smb:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:damage_cleanup_services:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:pc-cillin_internet_security:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:tmcomm.sys:1.5.1052:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:trend_micro_antirootkit_common_module:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:trend_micro_antispyware:3.0_sp2:*:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:trend_micro_antispyware:3.2_sp1:*:smb:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:trend_micro_antispyware:3.5:*:consumer:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:trend_micro_antivirus:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:vsapini.sys:3.320.1003:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0857",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "moinmoin",
            "product" : {
              "product_data" : [ {
                "product_name" : "moinmoin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://moinmoin.wikiwikiweb.de/MoinMoinRelease1.5/CHANGES",
          "name" : "http://moinmoin.wikiwikiweb.de/MoinMoinRelease1.5/CHANGES",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31871",
          "name" : "31871",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31872",
          "name" : "31872",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31873",
          "name" : "31873",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24096",
          "name" : "24096",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24117",
          "name" : "24117",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/31874",
          "name" : "31874",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22506",
          "name" : "22506",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-421-1",
          "name" : "USN-421-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0553",
          "name" : "ADV-2007-0553",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32377",
          "name" : "moinmoin-pageinfo-pagename-xss(32377)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.3_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.3_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.5_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-08T18:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0859",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "palm",
            "product" : {
              "product_data" : [ {
                "product_name" : "treo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "650",
                    "version_affected" : "="
                  }, {
                    "version_value" : "680",
                    "version_affected" : "="
                  }, {
                    "version_value" : "700p",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://discussion.treocentral.com/showthread.php?p=1199445&posted=1#post1199445",
          "name" : "http://discussion.treocentral.com/showthread.php?p=1199445&posted=1#post1199445",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33724",
          "name" : "33724",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2260",
          "name" : "2260",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460059/100/0/threaded",
          "name" : "20070213 SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460328/100/0/threaded",
          "name" : "20070216 Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460901/100/0/threaded",
          "name" : "20070222 SYMSA-2007-002-1: Palm OS Treo Find Feature System Password Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460908/100/0/threaded",
          "name" : "20070222 Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460911/100/0/threaded",
          "name" : "20070222 Re: Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460954/100/0/threaded",
          "name" : "20070222 RE: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22468",
          "name" : "22468",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/enterprise/research/SYMSA-2007-002.txt",
          "name" : "http://www.symantec.com/enterprise/research/SYMSA-2007-002.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32502",
          "name" : "palmos-findfeature-security-bypass(32502)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Find feature in Palm OS Treo smart phones operates despite the system password lock, which allows attackers with physical access to obtain sensitive information (memory contents) by doing (1) text searches or (2) paste operations after pressing certain keyboard shortcut keys."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:palm:treo:650:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:palm:treo:680:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:palm:treo:700p:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-16T00:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0860",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "laboratory_for_optical_and_computational_instrumentation",
            "product" : {
              "product_data" : [ {
                "product_name" : "local_calendar_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/458312/100/100/threaded",
          "name" : "20070127 local Calendar System v1.1 (lcStdLib.inc) Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458457/100/100/threaded",
          "name" : "20070128 Re: local Calendar System v1.1 (lcStdLib.inc) Remote File Include",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in local Calendar System 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) TEMPLATE_DIR parameter to (a) showinvoices.php, (b) showmonth.php, (c) showevents.php, (d) retrieveinvoice.php, (e) modifyitem.php, and (f) lookup_userid.php; or the LIBDIR parameter to (g) editevent.php, (h) resetpassword.php, (i) signup.php, showmonth.php, (j) showday.php, showevents.php, and lookup_userid.php. NOTE: this issue has been disputed by a third party, who states that the associated variables are set in config.php before use."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:laboratory_for_optical_and_computational_instrumentation:local_calendar_system:1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-09T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0861",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpcoin",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpcoin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "rc1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33591",
          "name" : "33591",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2230",
          "name" : "2230",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458064/100/200/threaded",
          "name" : "20070125 Re: phpCOIN <= RC-1 (modules/mail/index.php) Remote File Include Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458080/100/200/threaded",
          "name" : "20070125 phpCOIN <= RC-1 (modules/mail/index.php) Remote File Include Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  PHP remote file inclusion vulnerability in modules/mail/index.php in phpCOIN RC-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CCFG['_PKG_PATH_MDLS'] parameter.  NOTE: this issue has been disputed by a reliable third party, who states that a fatal error occurs before the relevant code is reached."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpcoin:phpcoin:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "rc1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-09T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0862",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnopaste",
            "product" : {
              "product_data" : [ {
                "product_name" : "gnopaste",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/458460/100/100/threaded",
          "name" : "20070129 gnopaste <= 0.5.3 (index.php) Remote File Include Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/458559/100/100/threaded",
          "name" : "20070129 Re: gnopaste <= 0.5.3 (index.php) Remote File Include Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  PHP remote file inclusion vulnerability in index.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via the GNP_REAL_PATH parameter.  NOTE: CVE and a third party dispute this issue, since GNP_REAL_PATH is a constant, not a variable."
        }, {
          "lang" : "en",
          "value" : "CVE and a third party dispute this issue, since GNP_REAL_PATH is a constant, not a variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnopaste:gnopaste:0.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnopaste:gnopaste:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.5.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-09T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0863",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trevorchan",
            "product" : {
              "product_data" : [ {
                "product_name" : "trevorchan",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33475",
          "name" : "33475",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017512",
          "name" : "1017512",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2007-January/001241.html",
          "name" : "20070115 [Bogus] [ilkerkandemir at mynet.com: Trevorchan <= v0.7 Remote File Include Vulnerability] (fwd)",
          "refsource" : "VIM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php.  NOTE: his issue has been disputed by reliable third parties, who state that the variable is set before use in config.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trevorchan:trevorchan:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-09T01:28Z",
    "lastModifiedDate" : "2008-11-15T06:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0864",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lushiwarplaner",
            "product" : {
              "product_data" : [ {
                "product_name" : "lushiwarplaner",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33167",
          "name" : "33167",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24079",
          "name" : "24079",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22470",
          "name" : "22470",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0538",
          "name" : "ADV-2007-0538",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32365",
          "name" : "lushiwarplaner-register-sql-injection(32365)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3288",
          "name" : "3288",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in register.php in LushiWarPlaner 1.0 allows remote attackers to inject arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lushiwarplaner:lushiwarplaner:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-09T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0865",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lushinews",
            "product" : {
              "product_data" : [ {
                "product_name" : "lushinews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33134",
          "name" : "33134",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24081",
          "name" : "24081",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22469",
          "name" : "22469",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0539",
          "name" : "ADV-2007-0539",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32360",
          "name" : "lushinews-comments-sql-injection(32360)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3287",
          "name" : "3287",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lushinews:lushinews:1.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lushinews:lushinews:1.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-09T01:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0866",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "openview_storage_data_protector",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.50",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33164",
          "name" : "33164",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24113",
          "name" : "24113",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1017614",
          "name" : "1017614",
          "refsource" : "SECTRACK",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459497/100/0/threaded",
          "name" : "HPSBMA02190",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22488",
          "name" : "22488",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0542",
          "name" : "ADV-2007-0542",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32386",
          "name" : "openview-dataprotector-privilege-escalation(32386)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in HP OpenView Storage Data Protector on HP-UX B.11.00, B.11.11, or B.11.23 allows local users to execute arbitrary code via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:openview_storage_data_protector:5.50:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-09T01:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0867",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "site-assistant",
            "product" : {
              "product_data" : [ {
                "product_name" : "site-assistant",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0990",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34695",
          "name" : "34695",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22467",
          "name" : "22467",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0541",
          "name" : "ADV-2007-0541",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32364",
          "name" : "siteassistant-menu-file-include(32364)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3285",
          "name" : "3285",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the paths[version] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:site-assistant:site-assistant:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0990"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-09T19:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0868",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "yahoo",
            "product" : {
              "product_data" : [ {
                "product_name" : "messenger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1046",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1065",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1232",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1249",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0.1347",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0.1351",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0.1355",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0.1356",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0.1358",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.1643",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.1750",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.1921",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.438",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.814",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.863",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0_2005.1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.0.209",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.0.239",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34696",
          "name" : "34696",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22407",
          "name" : "22407",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of service via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:5.0.1046:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:5.0.1065:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:5.0.1232:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:5.5.1249:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:5.6.0.1347:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:5.6.0.1351:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:5.6.0.1355:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:5.6.0.1356:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:5.6.0.1358:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:6.0.0.1643:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:6.0.0.1750:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:6.0.0.1921:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:7.0.438:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:7.5.0.814:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:8.0.0.863:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:8.0_2005.1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:8.1.0.209:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yahoo:messenger:8.1.0.239:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-09T19:28Z",
    "lastModifiedDate" : "2008-11-15T06:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0869",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jelsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "vbulletin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.6.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33129",
          "name" : "33129",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24085",
          "name" : "24085",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22466",
          "name" : "22466",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Attachment Manager (admincp/attachment.php) in Jelsoft vBulletin 3.6.4 allows remote attackers to inject arbitrary web script or HTML via the Extension field.  NOTE: this might be a duplicate of CVE-2007-0830.5.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jelsoft:vbulletin:3.6.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-09T19:28Z",
    "lastModifiedDate" : "2008-11-15T06:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0870",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0370.html",
          "name" : "20070215 Word flaw CVE-2007-0870 confirmed as code execution type issue",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33196",
          "name" : "33196",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24122",
          "name" : "24122",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.avertlabs.com/research/blog/?p=199",
          "name" : "http://www.avertlabs.com/research/blog/?p=199",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.avertlabs.com/research/blog/?p=206",
          "name" : "http://www.avertlabs.com/research/blog/?p=206",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/332404",
          "name" : "VU#332404",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.microsoft.com/technet/security/advisory/933052.mspx",
          "name" : "http://www.microsoft.com/technet/security/advisory/933052.mspx",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22567",
          "name" : "22567",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017653",
          "name" : "1017653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0607",
          "name" : "ADV-2007-0607",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1709",
          "name" : "ADV-2007-1709",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-024",
          "name" : "MS07-024",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32503",
          "name" : "word-document-string-code-execution(32503)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1860",
          "name" : "oval:org.mitre.oval:def:1860",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2000:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-11T21:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0871",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "extremepow",
            "product" : {
              "product_data" : [ {
                "product_name" : "extreme_file_hosting",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33181",
          "name" : "33181",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24088",
          "name" : "24088",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2231",
          "name" : "2231",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459562/100/0/threaded",
          "name" : "20070209 eXtreme File Hosting remote file upload vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22498",
          "name" : "22498",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32435",
          "name" : "extremefilehosting-compressed-file-upload(32435)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unrestricted file upload vulnerability in eXtremePow eXtreme File Hosting allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as (1) .rar.php or (2) .zip.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:extremepow:extreme_file_hosting:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0872",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "plain_old_webserver",
            "product" : {
              "product_data" : [ {
                "product_name" : "plain_old_webserver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33174",
          "name" : "33174",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2007/Feb/0196.html",
          "name" : "20070209 Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2007/Feb/0210.html",
          "name" : "20070209 Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24127",
          "name" : "24127",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22502",
          "name" : "22502",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0558",
          "name" : "ADV-2007-0558",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://addons.mozilla.org/firefox/3002/",
          "name" : "https://addons.mozilla.org/firefox/3002/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32467",
          "name" : "pow-httprequest-directory-traversal(32467)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary files via a .. (dot dot) in the URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_old_webserver:plain_old_webserver:0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_old_webserver:plain_old_webserver:0.0.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T19:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0873",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nabocorp",
            "product" : {
              "product_data" : [ {
                "product_name" : "nabopoll",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2007-February/001341.html",
          "name" : "20070215 [milw0rm] exploit 3305",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2643",
          "name" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2643",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33692",
          "name" : "33692",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2232",
          "name" : "2232",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459655/100/0/threaded",
          "name" : "20070210 nabopoll 1.1.2 sensitive file (admin without password)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22509",
          "name" : "22509",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32472",
          "name" : "nabopoll-adminscripts-unauthorized-access(32472)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3305",
          "name" : "3305",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_edit.php, (2) template_edit.php, or (3) survey_edit.php in admin/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nabocorp:nabopoll:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nabocorp:nabopoll:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0874",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "allons_voter",
            "product" : {
              "product_data" : [ {
                "product_name" : "allons_voter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2641",
          "name" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2641",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33690",
          "name" : "33690",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33691",
          "name" : "33691",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2234",
          "name" : "2234",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459652/100/0/threaded",
          "name" : "20070209 Allons_voter Version 1.0 xss and admin votes",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22508",
          "name" : "22508",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32431",
          "name" : "allonsvoter-admin-authentication-bypass(32431)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Allons_voter 1.0 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) admin_ajouter.php or (2) admin_supprimer.php.  NOTE: this could be leveraged to conduct cross-site scripting (XSS) attacks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:allons_voter:allons_voter:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0875",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mcrefer",
            "product" : {
              "product_data" : [ {
                "product_name" : "mcrefer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2642",
          "name" : "http://forums.avenir-geopolitique.net/viewtopic.php?t=2642",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33675",
          "name" : "33675",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2235",
          "name" : "2235",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459649/100/0/threaded",
          "name" : "20070209 mcRefer SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459796/100/200/threaded",
          "name" : "20070211 Re: mcRefer SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22507",
          "name" : "22507",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  SQL injection vulnerability in install.php in mcRefer allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this issue has been disputed by a third party, stating that the file does not use a SQL database."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mcrefer:mcrefer:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0876",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "qdig",
            "product" : {
              "product_data" : [ {
                "product_name" : "qdig",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006-06-24_dev",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32194",
          "name" : "32194",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24110",
          "name" : "24110",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=69837&release_id=485558",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=69837&release_id=485558",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459664/100/0/threaded",
          "name" : "20070210 [XSS] Qdig - Quick Digital Image Gallery Version 1.2.9.3 and -devel",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459791/100/0/threaded",
          "name" : "20070211 Re: [XSS] Qdig - Quick Digital Image Gallery Version 1.2.9.3 and -devel",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22510",
          "name" : "22510",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0555",
          "name" : "ADV-2007-0555",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32421",
          "name" : "qdig-qwd-xss(32421)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Quick Digital Image Gallery (Qdig) 1.2.9.3 and devel-20060624 allows remote attackers to inject arbitrary web script or HTML via the Qwd parameter to the top-level URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qdig:qdig:1.2.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qdig:qdig:2006-06-24_dev:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-12T19:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0877",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "march_networks",
            "product" : {
              "product_data" : [ {
                "product_name" : "3108_dvr",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "3204_dvr",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "4210_dvr",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "4310_dvr",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "4410_dvr",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/38098",
          "name" : "38098",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22497",
          "name" : "22497",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in March Networks DVR 3000 and 4000 Digital Video Recorders allows attackers to cause an unspecified denial of service.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:march_networks:3108_dvr:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:march_networks:3204_dvr:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:march_networks:4210_dvr:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:march_networks:4310_dvr:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:march_networks:4410_dvr:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T19:28Z",
    "lastModifiedDate" : "2008-11-15T06:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0878",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_mobile",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052293.html",
          "name" : "20070209 Denial Of Service in Internet Explorer for MS Windows Mobile 5.0",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32629",
          "name" : "32629",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459571/100/0/threaded",
          "name" : "20070209 Denial Of Service in Internet Explorer for MS Windows Mobile 5.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459584/100/0/threaded",
          "name" : "20070209 Re: Denial Of Service in Internet Explorer for MS Windows Mobile 5.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459591/100/0/threaded",
          "name" : "20070209 RE: Denial Of Service in Internet Explorer for MS Windows Mobile 5.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22500",
          "name" : "22500",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32394",
          "name" : "ie-mobile-wml-dos(32394)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Internet Explorer on Windows Mobile 5.0 allows remote attackers to cause a denial of service (loss of browser and other device functionality) via a malformed WML page, related to an \"overflow state.\" NOTE: it is possible that this issue is related to CVE-2007-0685."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_mobile:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T20:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0879",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "smidgeonsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "pebrowse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "professional_8.2.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/38134",
          "name" : "38134",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22501",
          "name" : "22501",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0665",
          "name" : "ADV-2007-0665",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32524",
          "name" : "smidgeonsoft-files-bo(32524)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in SmidgeonSoft PEBrowse Professional 8.2.1.0 allows user-assisted remote attackers to execute arbitrary code via certain executable files in PE format.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smidgeonsoft:pebrowse:professional_8.2.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-12T20:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0880",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "capital_request_forms",
            "product" : {
              "product_data" : [ {
                "product_name" : "capital_request_forms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33682",
          "name" : "33682",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459574/100/0/threaded",
          "name" : "20070209 Capital Request Forms Db Username and Password Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:capital_request_forms:capital_request_forms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T20:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0881",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openi-cms_group",
            "product" : {
              "product_data" : [ {
                "product_name" : "openi-cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://echo.or.id/adv/adv64-y3dips-2007.txt",
          "name" : "http://echo.or.id/adv/adv64-y3dips-2007.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33175",
          "name" : "33175",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24119",
          "name" : "24119",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22511",
          "name" : "22511",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0556",
          "name" : "ADV-2007-0556",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32423",
          "name" : "internalrange-oidir-file-include(32423)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3292",
          "name" : "3292",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the (1) config[oi_dir] and possibly (2) config[openi_dir] parameters to open-admin/plugins/site_protection/index.php.  NOTE: vector 2 might be the same as CVE-2006-4750."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that \"register_globals\" is enabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openi-cms_group:openi-cms:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T20:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0882",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sunos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://erratasec.blogspot.com/2007/02/trivial-remote-solaris-0day-disable.html",
          "name" : "http://erratasec.blogspot.com/2007/02/trivial-remote-solaris-0day-disable.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://isc.sans.org/diary.html?storyid=2220",
          "name" : "http://isc.sans.org/diary.html?storyid=2220",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31881",
          "name" : "31881",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2007/Feb/0217.html",
          "name" : "20070211 \"0day was the case that they gave me\"",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24120",
          "name" : "24120",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102802-1",
          "name" : "102802",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/881872",
          "name" : "VU#881872",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459831/100/0/threaded",
          "name" : "20070212 Re: [Full-disclosure] Solaris telnet vulnberability - how many on your network?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459843/100/0/threaded",
          "name" : "20070212 Solaris telnet vulnberability - how many on your network?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459855/100/0/threaded",
          "name" : "20070212 Re: [BLACKLIST] [Full-disclosure] Solaris telnet vulnberability - how many on yournetwork?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459980/100/0/threaded",
          "name" : "20070213 Re: [BLACKLIST] [Full-disclosure] Solaris telnet vulnberability - how many on yournetwork?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460086/100/100/threaded",
          "name" : "20070214 Solaris telnet vuln solutions digest and network risks",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460103/100/100/threaded",
          "name" : "20070214 RE: [Full-disclosure] Solaris telnet vulnberability - how many onyour network?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22512",
          "name" : "22512",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017625",
          "name" : "1017625",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-059A.html",
          "name" : "TA07-059A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0560",
          "name" : "ADV-2007-0560",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32434",
          "name" : "solaris-telnet-authentication-bypass(32434)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2202",
          "name" : "oval:org.mitre.oval:def:2202",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client \"-f\" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T20:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0883",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "second_rule_llc",
            "product" : {
              "product_data" : [ {
                "product_name" : "ip3_netaccess",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.9.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0235.html",
          "name" : "20070211 Arbitrary file disclosure vulnerability in IP3 NetAccess < 4.1.9.6",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/31912",
          "name" : "31912",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24118",
          "name" : "24118",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.devtarget.org/ip3-advisory-02-2007.txt",
          "name" : "http://www.devtarget.org/ip3-advisory-02-2007.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459806/100/0/threaded",
          "name" : "20070211 Arbitrary file disclosure vulnerability in IP3 NetAccess < 4.1.9.6",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22513",
          "name" : "22513",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017623",
          "name" : "1017623",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0615",
          "name" : "ADV-2007-0615",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32432",
          "name" : "ip3netaccess-getfile-directory-traversal(32432)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3294",
          "name" : "3294",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:second_rule_llc:ip3_netaccess:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.1.9.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T20:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0884",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "roaring_penguin",
            "product" : {
              "product_data" : [ {
                "product_name" : "mimedefang",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.60",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.roaringpenguin.com/pipermail/mimedefang/2007-February/032011.html",
          "name" : "[mimedefang] 20070209 SECURITY: MIMEDefang 2.61 is Released",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://osvdb.org/33171",
          "name" : "33171",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24133",
          "name" : "24133",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.mimedefang.org/node.php?id=62",
          "name" : "http://www.mimedefang.org/node.php?id=62",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22514",
          "name" : "22514",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0572",
          "name" : "ADV-2007-0572",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32466",
          "name" : "mimedefang-unspecified-bo(32466)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Roaring Penguin MIMEDefang 2.59 and 2.60 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors."
        }, {
          "lang" : "en",
          "value" : "Upgrade to 2.61"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:roaring_penguin:mimedefang:2.59:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:roaring_penguin:mimedefang:2.60:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T20:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0885",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rainbow_portal",
            "product" : {
              "product_data" : [ {
                "product_name" : "rainbow.zen",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rainbow_with_the_zen",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33683",
          "name" : "33683",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459590/100/0/threaded",
          "name" : "20070209 XSS in Rainbow with Rainbow.Zen",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22503",
          "name" : "22503",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32418",
          "name" : "rainbow-browseproject-xss(32418)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in jira/secure/BrowseProject.jspa in Rainbow with the Zen (Rainbow.Zen) extension allows remote attackers to inject arbitrary web script or HTML via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rainbow_portal:rainbow.zen:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rainbow_portal:rainbow_with_the_zen:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T20:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0886",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gecad_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "axigen_mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0b1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=117094708423302&w=2",
          "name" : "20070208 Axigen <2.0.0b1 DoS",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://osvdb.org/38133",
          "name" : "38133",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/24073",
          "name" : "24073",
          "refsource" : "SECUNIA",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22473",
          "name" : "22473",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32342",
          "name" : "axigen-memcpy-dos(32342)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3289",
          "name" : "3289",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via certain base64-encoded data on the pop3 port (110/tcp), which triggers an integer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gecad_technologies:axigen_mail_server:1.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gecad_technologies:axigen_mail_server:2.0.0b1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T23:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0887",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gecad_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "axigen_mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0b1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-476"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=117094708423302&w=2",
          "name" : "20070208 Axigen <2.0.0b1 DoS",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://osvdb.org/33165",
          "name" : "33165",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/24073",
          "name" : "24073",
          "refsource" : "SECUNIA",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22473",
          "name" : "22473",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32345",
          "name" : "axigen-nullpointer-dos(32345)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3290",
          "name" : "3290",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a base64-encoded \"*\\x00\" sequence on the imap port (143/tcp)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gecad_technologies:axigen_mail_server:1.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gecad_technologies:axigen_mail_server:2.0.0b1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T23:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0888",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kiwi_enterprises",
            "product" : {
              "product_data" : [ {
                "product_name" : "kiwi_cattools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24103",
          "name" : "24103",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2236",
          "name" : "2236",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.kiwisyslog.com/kb/idx/5/178/article/",
          "name" : "http://www.kiwisyslog.com/kb/idx/5/178/article/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33162",
          "name" : "33162",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459500/100/0/threaded",
          "name" : "20070208 TFTP directory traversal in Kiwi CatTools",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459933/100/0/threaded",
          "name" : "20070213 Re: TFTP directory traversal in Kiwi CatTools",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22490",
          "name" : "22490",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0536",
          "name" : "ADV-2007-0536",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32398",
          "name" : "kiwicattools-tftp-directory-traversal(32398)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read arbitrary files, and upload files to arbitrary locations, via ..// (dot dot) sequences in the pathname argument to an FTP (1) GET or (2) PUT command."
        }, {
          "lang" : "en",
          "value" : "This vulnerability is addressed in the following product update:\r\nKiwi Enterprises, Kiwi CatTools, 3.2.0 Beta"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kiwi_enterprises:kiwi_cattools:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0889",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kiwi_enterprises",
            "product" : {
              "product_data" : [ {
                "product_name" : "kiwi_cattools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33163",
          "name" : "33163",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24103",
          "name" : "24103",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2236",
          "name" : "2236",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459500/100/0/threaded",
          "name" : "20070208 TFTP directory traversal in Kiwi CatTools",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Kiwi CatTools before 3.2.0 beta uses weak encryption (\"reversible encoding\") for passwords, account names, and IP addresses in kiwidb-cattools.kdb, which might allow local users to gain sensitive information by decrypting the file.  NOTE: this issue could be leveraged with a directory traversal vulnerability for a remote attack vector."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kiwi_enterprises:kiwi_cattools:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0890",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cpanel",
            "product" : {
              "product_data" : [ {
                "product_name" : "webhost_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.2_stable_48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0_r85",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.1_r64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.9.1_r3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0_r82",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.6.0_r137",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.8.1_113",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.8.1_build84",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.8.2_118",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://changelog.cpanel.net/index.cgi",
          "name" : "http://changelog.cpanel.net/index.cgi",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32044",
          "name" : "32044",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24106",
          "name" : "24106",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459585/100/0/threaded",
          "name" : "20070208 local bug :[xxs] in whm",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22474",
          "name" : "22474",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0568",
          "name" : "ADV-2007-0568",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the password parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:6.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:6.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:6.4.2_stable_48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:9.1.0_r85:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:9.4.1_r64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:9.9.1_r3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:10.2.0_r82:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:10.6.0_r137:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:10.8.1_113:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:10.8.1_build84:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:10.8.2_118:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:10.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:webhost_manager:11_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0891",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "matthieu_aubry",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpmyvisites",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=117121596803908&w=2",
          "name" : "20070211 Multiple vulnerabilities in phpMyVisites",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://osvdb.org/33176",
          "name" : "33176",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/24124",
          "name" : "24124",
          "refsource" : "SECUNIA",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459792/100/0/threaded",
          "name" : "20070211 Multiple vulnerabilities in phpMyVisites",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22516",
          "name" : "22516",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0566",
          "name" : "ADV-2007-0566",
          "refsource" : "VUPEN",
          "tags" : [ "Not Applicable" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32430",
          "name" : "phpmyvisites-phpmyvisites-xss(32430)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the GetCurrentCompletePath function in phpmyvisites.php in phpMyVisites before 2.2 allows remote attackers to inject arbitrary web script or HTML via the query string."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:0.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.2_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-12T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0892",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "matthieu_aubry",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpmyvisites",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-93"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=117121596803908&w=2",
          "name" : "20070211 Multiple vulnerabilities in phpMyVisites",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://osvdb.org/33177",
          "name" : "33177",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459792/100/0/threaded",
          "name" : "20070211 Multiple vulnerabilities in phpMyVisites",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32428",
          "name" : "phpmyvisites-pagename-response-splitting(32428)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CRLF injection vulnerability in phpMyVisites before 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the url parameter, when the pagename parameter begins with \"FILE:\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:0.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.2_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0893",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "matthieu_aubry",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpmyvisites",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=117121596803908&w=2",
          "name" : "20070211 Multiple vulnerabilities in phpMyVisites",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://osvdb.org/33178",
          "name" : "33178",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459792/100/0/threaded",
          "name" : "20070211 Multiple vulnerabilities in phpMyVisites",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22516",
          "name" : "22516",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32433",
          "name" : "phpmyvisites-pmvckview-file-include(32433)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in phpMyVisites before 2.2 allows remote attackers to include arbitrary files via leading \"..\" sequences on the pmv_ck_view COOKIE parameter, which bypasses the protection scheme."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:0.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.2_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:matthieu_aubry:phpmyvisites:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0894",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mediawiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "mediawiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_beta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_beta4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_beta5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_beta6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_alpha1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_alpha2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_beta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_beta4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_rc4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.5_r14348",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugzilla.wikimedia.org/show_bug.cgi?id=8819",
          "name" : "http://bugzilla.wikimedia.org/show_bug.cgi?id=8819",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/33706",
          "name" : "33706",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33707",
          "name" : "33707",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33708",
          "name" : "33708",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33709",
          "name" : "33709",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://svn.wikimedia.org/viewvc/mediawiki?view=rev&revision=19681",
          "name" : "http://svn.wikimedia.org/viewvc/mediawiki?view=rev&revision=19681",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459793/100/0/threaded",
          "name" : "20070211 MediaWiki Full Path Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://zone14.free.fr/advisories/7/",
          "name" : "http://zone14.free.fr/advisories/7/",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32440",
          "name" : "mediawiki-multiple-scripts-path-disclosure(32440)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.3.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4_beta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4_beta4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4_beta5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4_beta6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_alpha1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_alpha2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_beta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_beta4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_rc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.5_r14348:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.9.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.9.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-12T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0895",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sunos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24082",
          "name" : "24082",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24405",
          "name" : "24405",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102782-1",
          "name" : "102782",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-102.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-102.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/31880",
          "name" : "31880",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0543",
          "name" : "ADV-2007-0543",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32399",
          "name" : "solaris-rm-dos(32399)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8272",
          "name" : "oval:org.mitre.oval:def:8272",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a \"..\" directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:N/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T01:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0896",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "sage",
            "product" : {
              "product_data" : [ {
                "product_name" : "sage",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_beta_3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/jp/JVN%2384430861/index.html",
          "name" : "JVN#84430861",
          "refsource" : "JVN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://mozdev.org/bugs/show_bug.cgi?id=16320",
          "name" : "http://mozdev.org/bugs/show_bug.cgi?id=16320",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33131",
          "name" : "33131",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://sage.mozdev.org/blog/archives/2007/1/sage_1_3_10_released.html",
          "name" : "http://sage.mozdev.org/blog/archives/2007/1/sage_1_3_10_released.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24086",
          "name" : "24086",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22493",
          "name" : "22493",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017624",
          "name" : "1017624",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32395",
          "name" : "sage-rssfeed-xss(32395)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a \"<SCRIPT/=''SRC='\" sequence in an RSS feed, a different vulnerability than CVE-2006-4712."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sage:sage:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sage:sage:1.0_beta_3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sage:sage:1.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sage:sage:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-13T11:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0897",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clam_anti-virus",
            "product" : {
              "product_data" : [ {
                "product_name" : "clamav",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.15",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.20",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.21",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.22",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.23",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.24",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.51",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.52",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.53",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.54",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.60",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.60p",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.65",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.67",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.68",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.68.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.70",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.71",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.72",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.73",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.74",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.75",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.75.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.80",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.80_rc1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.80_rc2",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.80_rc3",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.80_rc4",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.81",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.81_rc1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.82",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.83",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.84",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.84_rc1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.84_rc2",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.85",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.85.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.86",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.86.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.86.2",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.86_rc1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.87",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.87.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.88",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.88.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.88.3",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.88.4",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "0.88.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=475",
          "name" : "20070215 Multiple Vendor ClamAV CAB File Denial of Service Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Feb/0004.html",
          "name" : "SUSE-SA:2007:017",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32283",
          "name" : "32283",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24183",
          "name" : "24183",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24187",
          "name" : "24187",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24192",
          "name" : "24192",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24319",
          "name" : "24319",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24332",
          "name" : "24332",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24425",
          "name" : "24425",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-03.xml",
          "name" : "GLSA-200703-03",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1263",
          "name" : "DSA-1263",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:043",
          "name" : "MDKSA-2007:043",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22580",
          "name" : "22580",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017659",
          "name" : "1017659",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0623",
          "name" : "ADV-2007-0623",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32531",
          "name" : "clamav-cabfile-dos(32531)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor."
        }, {
          "lang" : "en",
          "value" : "This vulnerability is addressed in the following product release:\r\nClam AntiVirus, ClamAV, 0.90 Stable"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.15"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.20"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.21"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.22"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.23"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.24"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.51"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.52"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.53"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.54"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.60"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.60p"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.65"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.67"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.68"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.68.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.70"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.71"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.72"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.73"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.74"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.75"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.75.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.80"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.80_rc1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.80_rc2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.80_rc3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.80_rc4"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.81"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.81_rc1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.82"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.83"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.84"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.84_rc1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.84_rc2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.85"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.85.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.86"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.86.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.86.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.86_rc1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.87"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.87.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.88"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.88.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.88.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.88.4"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.88.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-16T19:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0898",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clam_anti-virus",
            "product" : {
              "product_data" : [ {
                "product_name" : "clamav",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.60p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.65",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.67",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.68",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.68.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.70",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.71",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.72",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.73",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.74",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.75",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.75.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80_rc4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.81",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.81_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.82",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.83",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.84",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.84_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.84_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.85",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.85.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.87",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.87.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307562",
          "name" : "http://docs.info.apple.com/article.html?artnum=307562",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=476",
          "name" : "20070215 Multiple Vendor ClamAV MIME Parsing Directory Traversal Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
          "name" : "APPLE-SA-2008-03-18",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Feb/0004.html",
          "name" : "SUSE-SA:2007:017",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32282",
          "name" : "32282",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24183",
          "name" : "24183",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24187",
          "name" : "24187",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24192",
          "name" : "24192",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24319",
          "name" : "24319",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24332",
          "name" : "24332",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24425",
          "name" : "24425",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29420",
          "name" : "29420",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-03.xml",
          "name" : "GLSA-200703-03",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1263",
          "name" : "DSA-1263",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:043",
          "name" : "MDKSA-2007:043",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22581",
          "name" : "22581",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017660",
          "name" : "1017660",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0623",
          "name" : "ADV-2007-0623",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0924/references",
          "name" : "ADV-2008-0924",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32535",
          "name" : "clamav-mimeheader-directory-traversal(32535)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the id MIME header parameter in a multi-part message."
        }, {
          "lang" : "en",
          "value" : "This vulnerability is addressed in the following product release:\r\nClam Anti-Virus, ClamAV, 0.90"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.60p:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.65:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.67:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.68:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.68.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.70:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.71:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.72:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.73:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.74:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.75:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.75.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.80:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.80_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.80_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.80_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.80_rc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.81:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.81_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.82:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.83:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.84:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.84_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.84_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.85:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.85.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.86:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.86.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.86.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.86_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.87:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.87.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.88:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.88.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.88.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.88.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.88.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-16T19:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0899",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clamav",
            "product" : {
              "product_data" : [ {
                "product_name" : "clamav",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.60p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.65",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.66",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.67",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.67-1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.68",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.68.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.70",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.70.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.71",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.71.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.72",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.72.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.73",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.73.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.74",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.74.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.75",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.75.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.75.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80_rc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.81",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.81.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.82",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.82.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.83",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.83.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.84",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.84.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.85",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.85.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.85.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.87",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.87.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.87.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.7_p0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.88.7_p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.1_p0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.2_p0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.3_p0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.90.3_p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.91",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.91.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.91.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.91.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.91.2_p0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.92",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.92.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.92.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.92_p0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.93",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.93.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.93.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.93.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.93.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.94",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.94.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.94.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.94.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.95",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.95.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.95.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.95.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.95.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.96",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.96.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.96.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.96.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.96.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.96.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.96.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.97",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.97.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.97.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.97.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.97.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.97.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.97.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.97.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.97.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.97.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.98.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.98.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.98.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.98.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.98.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.98.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.98.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-787"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://security-tracker.debian.org/tracker/CVE-2007-0899",
          "name" : "https://security-tracker.debian.org/tracker/CVE-2007-0899",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "There is a possible heap overflow in libclamav/fsg.c before 0.100.0."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "0.100.0"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2019-11-06T04:15Z",
    "lastModifiedDate" : "2020-08-18T15:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0900",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tagit",
            "product" : {
              "product_data" : [ {
                "product_name" : "tagboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.b_build_2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://advisories.echo.or.id/adv/adv65-K-159-2007.txt",
          "name" : "http://advisories.echo.or.id/adv/adv65-K-159-2007.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34603",
          "name" : "34603",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34604",
          "name" : "34604",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34605",
          "name" : "34605",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34606",
          "name" : "34606",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34607",
          "name" : "34607",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34608",
          "name" : "34608",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34609",
          "name" : "34609",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34610",
          "name" : "34610",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34611",
          "name" : "34611",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34612",
          "name" : "34612",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34613",
          "name" : "34613",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34614",
          "name" : "34614",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34615",
          "name" : "34615",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34616",
          "name" : "34616",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34617",
          "name" : "34617",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34618",
          "name" : "34618",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22518",
          "name" : "22518",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0557",
          "name" : "ADV-2007-0557",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32436",
          "name" : "tagit-multiplescripts-file-include(32436)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file inclusion vulnerabilities in TagIt! Tagboard 2.1.B Build 2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) configpath parameter to (a) tagviewer.php, (b) tag_process.php, and (c) CONFIG/errmsg.inc.php; and (d) addTagmin.php, (e) ban_watch.php, (f) delTagmin.php, (g) delTag.php, (h) editTagmin.php, (i) editTag.php, (j) manageTagmins.php, and (k) verify.php in tagmin/; the (2) adminpath parameter to (l) tagviewer.php, (m) tag_process.php, and (n) tagmin/index.php; and the (3) admin parameter to (o) readconf.php, (p) updateconf.php, (q) updatefilter.php, and (r) wordfilter.php in tagmin/; different vectors than CVE-2006-5249."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tagit:tagboard:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1.b_build_2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T20:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0901",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "moinmoin",
            "product" : {
              "product_data" : [ {
                "product_name" : "moinmoin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33172",
          "name" : "33172",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24138",
          "name" : "24138",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24244",
          "name" : "24244",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22515",
          "name" : "22515",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-423-1",
          "name" : "USN-423-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Info pages in MoinMoin 1.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) hitcounts and (2) general parameters, different vectors than CVE-2007-0857.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T20:28Z",
    "lastModifiedDate" : "2008-11-15T06:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0902",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "moinmoin",
            "product" : {
              "product_data" : [ {
                "product_name" : "moinmoin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33173",
          "name" : "33173",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24138",
          "name" : "24138",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24244",
          "name" : "24244",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22515",
          "name" : "22515",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-423-1",
          "name" : "USN-423-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the \"Show debugging information\" feature in MoinMoin 1.5.7 allows remote attackers to obtain sensitive information.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moinmoin:moinmoin:1.5.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T20:28Z",
    "lastModifiedDate" : "2008-11-15T06:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0903",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "process-one",
            "product" : {
              "product_data" : [ {
                "product_name" : "ejabberd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33179",
          "name" : "33179",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24075",
          "name" : "24075",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_113/",
          "name" : "http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_113/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22525",
          "name" : "22525",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0570",
          "name" : "ADV-2007-0570",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32437",
          "name" : "ejabberd-modrosterodbc-unspecified(32437)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:process-one:ejabberd:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:process-one:ejabberd:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:process-one:ejabberd:0.9.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:process-one:ejabberd:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:process-one:ejabberd:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:process-one:ejabberd:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:process-one:ejabberd:1.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T20:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0904",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lightro",
            "product" : {
              "product_data" : [ {
                "product_name" : "lightro_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/34598",
          "name" : "34598",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0540",
          "name" : "ADV-2007-0540",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32347",
          "name" : "lightro-index-sql-injection(32347)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3286",
          "name" : "3286",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in projects.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lightro:lightro_cms:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T20:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0905",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "trustix",
            "product" : {
              "product_data" : [ {
                "product_name" : "secure_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/32768",
          "name" : "32768",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24089",
          "name" : "24089",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24419",
          "name" : "24419",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html",
          "name" : "OpenPKG-SA-2007.010",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/ChangeLog-5.php#5.2.1",
          "name" : "http://www.php.net/ChangeLog-5.php#5.2.1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/releases/5_2_1.php",
          "name" : "http://www.php.net/releases/5_2_1.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22496",
          "name" : "22496",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0009/",
          "name" : "2007-0009",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0546",
          "name" : "ADV-2007-0546",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension.  NOTE: it is possible that this issue is a duplicate of CVE-2006-6383."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:patch2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.3:patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2:*:dev:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:trustix:secure_linux:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:trustix:secure_linux:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T23:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0906",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "trustix",
            "product" : {
              "product_data" : [ {
                "product_name" : "secure_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc",
          "name" : "20070201-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html",
          "name" : "SUSE-SA:2007:044",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html",
          "name" : "SUSE-SA:2007:020",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34706",
          "name" : "34706",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34707",
          "name" : "34707",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34708",
          "name" : "34708",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34709",
          "name" : "34709",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34710",
          "name" : "34710",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34711",
          "name" : "34711",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34712",
          "name" : "34712",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34713",
          "name" : "34713",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34714",
          "name" : "34714",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/34715",
          "name" : "34715",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0089.html",
          "name" : "RHSA-2007:0089",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24089",
          "name" : "24089",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24195",
          "name" : "24195",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24217",
          "name" : "24217",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24236",
          "name" : "24236",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24248",
          "name" : "24248",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24284",
          "name" : "24284",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24295",
          "name" : "24295",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24322",
          "name" : "24322",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24419",
          "name" : "24419",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24421",
          "name" : "24421",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24432",
          "name" : "24432",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24514",
          "name" : "24514",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24606",
          "name" : "24606",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24642",
          "name" : "24642",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24945",
          "name" : "24945",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/26048",
          "name" : "26048",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-21.xml",
          "name" : "GLSA-200703-21",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:048",
          "name" : "MDKSA-2007:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html",
          "name" : "OpenPKG-SA-2007.010",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/32776",
          "name" : "32776",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/ChangeLog-5.php#5.2.1",
          "name" : "http://www.php.net/ChangeLog-5.php#5.2.1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/releases/5_2_1.php",
          "name" : "http://www.php.net/releases/5_2_1.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0076.html",
          "name" : "RHSA-2007:0076",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0081.html",
          "name" : "RHSA-2007:0081",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0082.html",
          "name" : "RHSA-2007:0082",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0088.html",
          "name" : "RHSA-2007:0088",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461462/100/0/threaded",
          "name" : "20070227 rPSA-2007-0043-1 php php-mysql php-pgsql",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/466166/100/0/threaded",
          "name" : "20070418 rPSA-2007-0073-1 php php-mysql php-pgsql",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22496",
          "name" : "22496",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017671",
          "name" : "1017671",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0009/",
          "name" : "2007-0009",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-424-1",
          "name" : "USN-424-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-424-2",
          "name" : "USN-424-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us.debian.org/security/2007/dsa-1264",
          "name" : "DSA-1264",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0546",
          "name" : "ADV-2007-0546",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1088",
          "name" : "https://issues.rpath.com/browse/RPL-1088",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1268",
          "name" : "https://issues.rpath.com/browse/RPL-1268",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8992",
          "name" : "oval:org.mitre.oval:def:8992",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions.  NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885).  NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function (CVE-2007-1825)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:patch2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.3:patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2:*:dev:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:trustix:secure_linux:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:trustix:secure_linux:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T23:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0907",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "trustix",
            "product" : {
              "product_data" : [ {
                "product_name" : "secure_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc",
          "name" : "20070201-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html",
          "name" : "SUSE-SA:2007:020",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32767",
          "name" : "32767",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0089.html",
          "name" : "RHSA-2007:0089",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24089",
          "name" : "24089",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24195",
          "name" : "24195",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24217",
          "name" : "24217",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24236",
          "name" : "24236",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24248",
          "name" : "24248",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24284",
          "name" : "24284",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24295",
          "name" : "24295",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24322",
          "name" : "24322",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24419",
          "name" : "24419",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24421",
          "name" : "24421",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24432",
          "name" : "24432",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24514",
          "name" : "24514",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24606",
          "name" : "24606",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24642",
          "name" : "24642",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-21.xml",
          "name" : "GLSA-200703-21",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:048",
          "name" : "MDKSA-2007:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html",
          "name" : "OpenPKG-SA-2007.010",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/ChangeLog-5.php#5.2.1",
          "name" : "http://www.php.net/ChangeLog-5.php#5.2.1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/releases/5_2_1.php",
          "name" : "http://www.php.net/releases/5_2_1.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0076.html",
          "name" : "RHSA-2007:0076",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0081.html",
          "name" : "RHSA-2007:0081",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0082.html",
          "name" : "RHSA-2007:0082",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0088.html",
          "name" : "RHSA-2007:0088",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461462/100/0/threaded",
          "name" : "20070227 rPSA-2007-0043-1 php php-mysql php-pgsql",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22496",
          "name" : "22496",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017671",
          "name" : "1017671",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0009/",
          "name" : "2007-0009",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-424-1",
          "name" : "USN-424-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-424-2",
          "name" : "USN-424-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us.debian.org/security/2007/dsa-1264",
          "name" : "DSA-1264",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0546",
          "name" : "ADV-2007-0546",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1088",
          "name" : "https://issues.rpath.com/browse/RPL-1088",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11321",
          "name" : "oval:org.mitre.oval:def:11321",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer underflow in PHP before 5.2.1 allows attackers to cause a denial of service via unspecified vectors involving the sapi_header_op function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:patch2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.3:patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2:*:dev:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:trustix:secure_linux:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:trustix:secure_linux:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T23:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0908",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc",
          "name" : "20070201-01-P",
          "refsource" : "SGI",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html",
          "name" : "SUSE-SA:2007:020",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://osvdb.org/32766",
          "name" : "32766",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0089.html",
          "name" : "RHSA-2007:0089",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24089",
          "name" : "24089",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24195",
          "name" : "24195",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24217",
          "name" : "24217",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24236",
          "name" : "24236",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24248",
          "name" : "24248",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24284",
          "name" : "24284",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24295",
          "name" : "24295",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24322",
          "name" : "24322",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24419",
          "name" : "24419",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24421",
          "name" : "24421",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24432",
          "name" : "24432",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24514",
          "name" : "24514",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24606",
          "name" : "24606",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24642",
          "name" : "24642",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-21.xml",
          "name" : "GLSA-200703-21",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2321",
          "name" : "2321",
          "refsource" : "SREASON",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:048",
          "name" : "MDKSA-2007:048",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html",
          "name" : "OpenPKG-SA-2007.010",
          "refsource" : "OPENPKG",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.php.net/ChangeLog-5.php#5.2.1",
          "name" : "http://www.php.net/ChangeLog-5.php#5.2.1",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.php.net/releases/5_2_1.php",
          "name" : "http://www.php.net/releases/5_2_1.php",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.php-security.org/MOPB/MOPB-11-2007.html",
          "name" : "http://www.php-security.org/MOPB/MOPB-11-2007.html",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0076.html",
          "name" : "RHSA-2007:0076",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0081.html",
          "name" : "RHSA-2007:0081",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0082.html",
          "name" : "RHSA-2007:0082",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0088.html",
          "name" : "RHSA-2007:0088",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461462/100/0/threaded",
          "name" : "20070227 rPSA-2007-0043-1 php php-mysql php-pgsql",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22496",
          "name" : "22496",
          "refsource" : "BID",
          "tags" : [ "Patch", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22806",
          "name" : "22806",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017671",
          "name" : "1017671",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0009/",
          "name" : "2007-0009",
          "refsource" : "TRUSTIX",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-424-1",
          "name" : "USN-424-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-424-2",
          "name" : "USN-424-2",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.us.debian.org/security/2007/dsa-1264",
          "name" : "DSA-1264",
          "refsource" : "DEBIAN",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0546",
          "name" : "ADV-2007-0546",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required", "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32493",
          "name" : "php-wddx-information-disclosure(32493)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1088",
          "name" : "https://issues.rpath.com/browse/RPL-1088",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11185",
          "name" : "oval:org.mitre.oval:def:11185",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element that contains a variable with a string name before a numerical variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:beta4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:beta_4_patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "4.0.0",
          "versionEndExcluding" : "4.4.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.0.0",
          "versionEndExcluding" : "5.2.1"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T23:28Z",
    "lastModifiedDate" : "2018-10-30T16:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0909",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "trustix",
            "product" : {
              "product_data" : [ {
                "product_name" : "secure_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc",
          "name" : "20070201-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html",
          "name" : "SUSE-SA:2007:020",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32764",
          "name" : "32764",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32765",
          "name" : "32765",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0089.html",
          "name" : "RHSA-2007:0089",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24089",
          "name" : "24089",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24195",
          "name" : "24195",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24217",
          "name" : "24217",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24236",
          "name" : "24236",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24248",
          "name" : "24248",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24284",
          "name" : "24284",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24295",
          "name" : "24295",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24322",
          "name" : "24322",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24419",
          "name" : "24419",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24421",
          "name" : "24421",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24432",
          "name" : "24432",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24514",
          "name" : "24514",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24606",
          "name" : "24606",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24642",
          "name" : "24642",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-21.xml",
          "name" : "GLSA-200703-21",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:048",
          "name" : "MDKSA-2007:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html",
          "name" : "OpenPKG-SA-2007.010",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/ChangeLog-5.php#5.2.1",
          "name" : "http://www.php.net/ChangeLog-5.php#5.2.1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/releases/5_2_1.php",
          "name" : "http://www.php.net/releases/5_2_1.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0076.html",
          "name" : "RHSA-2007:0076",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0081.html",
          "name" : "RHSA-2007:0081",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0082.html",
          "name" : "RHSA-2007:0082",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0088.html",
          "name" : "RHSA-2007:0088",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461462/100/0/threaded",
          "name" : "20070227 rPSA-2007-0043-1 php php-mysql php-pgsql",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22496",
          "name" : "22496",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017671",
          "name" : "1017671",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0009/",
          "name" : "2007-0009",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-424-1",
          "name" : "USN-424-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-424-2",
          "name" : "USN-424-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us.debian.org/security/2007/dsa-1264",
          "name" : "DSA-1264",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0546",
          "name" : "ADV-2007-0546",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1088",
          "name" : "https://issues.rpath.com/browse/RPL-1088",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9722",
          "name" : "oval:org.mitre.oval:def:9722",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:patch2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.3:patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2:*:dev:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:trustix:secure_linux:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:trustix:secure_linux:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T23:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0910",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "trustix",
            "product" : {
              "product_data" : [ {
                "product_name" : "secure_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc",
          "name" : "20070201-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html",
          "name" : "SUSE-SA:2007:020",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/32763",
          "name" : "32763",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0089.html",
          "name" : "RHSA-2007:0089",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24089",
          "name" : "24089",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24195",
          "name" : "24195",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24217",
          "name" : "24217",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24236",
          "name" : "24236",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24248",
          "name" : "24248",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24284",
          "name" : "24284",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24295",
          "name" : "24295",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24322",
          "name" : "24322",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24419",
          "name" : "24419",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24421",
          "name" : "24421",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24432",
          "name" : "24432",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24514",
          "name" : "24514",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24606",
          "name" : "24606",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24642",
          "name" : "24642",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24945",
          "name" : "24945",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-21.xml",
          "name" : "GLSA-200703-21",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:048",
          "name" : "MDKSA-2007:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html",
          "name" : "OpenPKG-SA-2007.010",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/ChangeLog-5.php#5.2.1",
          "name" : "http://www.php.net/ChangeLog-5.php#5.2.1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/releases/5_2_1.php",
          "name" : "http://www.php.net/releases/5_2_1.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0076.html",
          "name" : "RHSA-2007:0076",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0081.html",
          "name" : "RHSA-2007:0081",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0082.html",
          "name" : "RHSA-2007:0082",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0088.html",
          "name" : "RHSA-2007:0088",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/461462/100/0/threaded",
          "name" : "20070227 rPSA-2007-0043-1 php php-mysql php-pgsql",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/466166/100/0/threaded",
          "name" : "20070418 rPSA-2007-0073-1 php php-mysql php-pgsql",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22496",
          "name" : "22496",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017671",
          "name" : "1017671",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2007/0009/",
          "name" : "2007-0009",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-424-1",
          "name" : "USN-424-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-424-2",
          "name" : "USN-424-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us.debian.org/security/2007/dsa-1264",
          "name" : "DSA-1264",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0546",
          "name" : "ADV-2007-0546",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1088",
          "name" : "https://issues.rpath.com/browse/RPL-1088",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-1268",
          "name" : "https://issues.rpath.com/browse/RPL-1268",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9514",
          "name" : "oval:org.mitre.oval:def:9514",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in PHP before 5.2.1 allows attackers to \"clobber\" certain super-global variables via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:3.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:patch2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.3:patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.7:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2:*:dev:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.2.0"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:trustix:secure_linux:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:trustix:secure_linux:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T23:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0911",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://cvs.php.net/viewvc.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.36&r2=1.445.2.14.2.37",
          "name" : "http://cvs.php.net/viewvc.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.36&r2=1.445.2.14.2.37",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html",
          "name" : "SUSE-SA:2007:020",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=php-dev&m=117104930526516&w=2",
          "name" : "[php-dev] 20070209 PHP 5.2.1 crashing Apache/IIS...",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=php-dev&m=117106751715609&w=2",
          "name" : "[php-dev] 20070210 Re: PHP 5.2.1 crashing Apache/IIS...",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33952",
          "name" : "33952",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24514",
          "name" : "24514",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24606",
          "name" : "24606",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-21.xml",
          "name" : "GLSA-200703-21",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459856/100/0/threaded",
          "name" : "20070209 PHP 5.2.1 crash bug",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22505",
          "name" : "22505",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Off-by-one error in the str_ireplace function in PHP 5.2.1 might allow context-dependent attackers to cause a denial of service (crash)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-13T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0912",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jportal",
            "product" : {
              "product_data" : [ {
                "product_name" : "jportal_web_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33712",
          "name" : "33712",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2239",
          "name" : "2239",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459827/100/0/threaded",
          "name" : "20070211 Jportal 2.3.1 CSRF vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32458",
          "name" : "jportal-admin-csrf(32458)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-Site Request Forgery (CSRF) vulnerability in admin/admin.adm.php in Jportal 2.3.1, and possibly earlier, allows remote attackers to perform privileged actions as administrators by tricking the admin into accessing a URL with modified arguments to admin/admin.adm.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jportal:jportal_web_server:2.3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-13T23:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0913",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerpoint",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35763",
          "name" : "35763",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-021312-5133-99&tabid=2",
          "name" : "http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-021312-5133-99&tabid=2",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G.  NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006-5296, CVE-2006-4694, CVE-2006-3876, CVE-2006-3877, or older issues."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-14T01:28Z",
    "lastModifiedDate" : "2008-11-15T06:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0914",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33194",
          "name" : "33194",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24166",
          "name" : "24166",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102796-1",
          "name" : "102796",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22550",
          "name" : "22550",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017649",
          "name" : "1017649",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0588",
          "name" : "ADV-2007-0588",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32484",
          "name" : "solaris-tcp-race-condition-dos(32484)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2120",
          "name" : "oval:org.mitre.oval:def:2120",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Race condition in the TCP subsystem for Solaris 10 allows remote attackers to cause a denial of service (system panic) via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T02:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0915",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "hp-ux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=474",
          "name" : "20070213 Hewlett-Packard HP-UX SLSd Arbitrary File Creation Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33186",
          "name" : "33186",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24169",
          "name" : "24169",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22551",
          "name" : "22551",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017630",
          "name" : "1017630",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0590",
          "name" : "ADV-2007-0590",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00862809",
          "name" : "HPSBUX02191",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32471",
          "name" : "hpux-slsd-privilege-escalation(32471)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Distributed SLS daemon (SLSd) on HP-UX B.11.11 allows remote attackers to overwrite arbitrary files and gain privileges via a crafted RPC request."
        }, {
          "lang" : "en",
          "value" : "See HP's advisory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0916",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "hp-ux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.23",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33198",
          "name" : "33198",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24173",
          "name" : "24173",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22546",
          "name" : "22546",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017629",
          "name" : "1017629",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0596",
          "name" : "ADV-2007-0596",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00863839",
          "name" : "HPSBUX02192",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32468",
          "name" : "hpux-arpa-dos(32468)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5239",
          "name" : "oval:org.mitre.oval:def:5239",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.23:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T02:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0917",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "ios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.3t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ym",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ys",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4mr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xb",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33052",
          "name" : "33052",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24142",
          "name" : "24142",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a00807e0a5b.shtml",
          "name" : "20070213 Multiple IOS IPS Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html",
          "name" : "http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22549",
          "name" : "22549",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017631",
          "name" : "1017631",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0597",
          "name" : "ADV-2007-0597",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32473",
          "name" : "cisco-ios-ips-security-bypass(32473)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5858",
          "name" : "oval:org.mitre.oval:def:5858",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers to bypass IPS signatures that use regular expressions via fragmented packets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3ym:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3ys:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4mr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xb:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T02:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0918",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "ios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.3xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ym",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ys",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4mr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yi",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33053",
          "name" : "33053",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24142",
          "name" : "24142",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a00807e0a5b.shtml",
          "name" : "20070213 Multiple IOS IPS Vulnerabilities",
          "refsource" : "CISCO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html",
          "name" : "http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22549",
          "name" : "22549",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017631",
          "name" : "1017631",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0597",
          "name" : "ADV-2007-0597",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32474",
          "name" : "cisco-ios-ips-dos(32474)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5832",
          "name" : "oval:org.mitre.oval:def:5832",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations that are not properly handled by the regular expression feature, as demonstrated using the 3123.0 (Netbus Pro Traffic) signature."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3xx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3xy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3yg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3yk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3ym:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3yq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3ys:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.3yz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.4mr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.4t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.4xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ios:12.4xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yi:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T02:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0919",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nickolas_grigoriadis",
            "product" : {
              "product_data" : [ {
                "product_name" : "mini_web_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2007-February/001315.html",
          "name" : "20060213 Verified: dot in Miniwebsvr 0.0.6",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33513",
          "name" : "33513",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2248",
          "name" : "2248",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459829/100/0/threaded",
          "name" : "20070211 Miniwebsvr 0.0.6 - Directory traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22523",
          "name" : "22523",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32451",
          "name" : "miniwebsvr-unspecified-directory-traversal(32451)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to list the directory immediately above the web root via a ..%00 sequence in the URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nickolas_grigoriadis:mini_web_server:0.0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0920",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "philboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "philboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.14",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35678",
          "name" : "35678",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22532",
          "name" : "22532",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0600",
          "name" : "ADV-2007-0600",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32442",
          "name" : "philboard-philboardforum-sql-injection(32442)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3295",
          "name" : "3295",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:philboard:philboard:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.14"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2017-10-19T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0921",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "radical_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "portal_search",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33713",
          "name" : "33713",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2247",
          "name" : "2247",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459794/100/0/threaded",
          "name" : "20070212 Radical Technologies - Portal Search- multiple XSS issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22533",
          "name" : "22533",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32460",
          "name" : "portalsearch-frame-url-spoofing(32460)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Portal Search allows remote attackers to redirect a URL to an arbitrary web site by placing the URL in the query string to the top-level URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:radical_technologies:portal_search:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.4
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0922",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "radical_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "portal_search",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33714",
          "name" : "33714",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2247",
          "name" : "2247",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459794/100/0/threaded",
          "name" : "20070212 Radical Technologies - Portal Search- multiple XSS issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22533",
          "name" : "22533",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in buscador/buscador.htm in Portal Search allows remote attackers to inject arbitrary web script or HTML via the query string."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:radical_technologies:portal_search:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0923",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "radical_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "portal_search",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33715",
          "name" : "33715",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2247",
          "name" : "2247",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459794/100/0/threaded",
          "name" : "20070212 Radical Technologies - Portal Search- multiple XSS issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22533",
          "name" : "22533",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32452",
          "name" : "portalsearch-buscador-info-disclosure(32452)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "buscador/buscador.htm in Portal Search allows remote attackers to obtain sensitive information (business logic) via a query string composed of a search for certain characters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:radical_technologies:portal_search:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0924",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "till_gerken",
            "product" : {
              "product_data" : [ {
                "product_name" : "phppolls",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33694",
          "name" : "33694",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2242",
          "name" : "2242",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459789/100/0/threaded",
          "name" : "20070211 phpPolls 1.0.3 (acces to sensitive file)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22522",
          "name" : "22522",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Till Gerken phpPolls 1.0.3 allows remote attackers to bypass authentication and perform certain administrative actions via a direct request to phpPollAdmin.php3.  NOTE: this issue might subsume CVE-2006-3764."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:till_gerken:phppolls:1.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0925",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "communityserver.org",
            "product" : {
              "product_data" : [ {
                "product_name" : "community_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33717",
          "name" : "33717",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2241",
          "name" : "2241",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459848/100/0/threaded",
          "name" : "20070209 XSS in communityserver !",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22529",
          "name" : "22529",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32444",
          "name" : "communityserver-searchresults-xss(32444)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:communityserver.org:community_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0926",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kvguestbook",
            "product" : {
              "product_data" : [ {
                "product_name" : "kvguestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33710",
          "name" : "33710",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2246",
          "name" : "2246",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459799/100/0/threaded",
          "name" : "20070211 KvGuestbook Remote Add Admin Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The dologin function in guestbook.php in KvGuestbook 1.0 Beta allows remote attackers to gain administrative privileges, probably via modified $mysql['pass'] and $gbpass variables."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kvguestbook:kvguestbook:1.0_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0927",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "utorrent",
            "product" : {
              "product_data" : [ {
                "product_name" : "utorrent",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24130",
          "name" : "24130",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/33180",
          "name" : "33180",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/460346/100/0/threaded",
          "name" : "20070216 utorrent issue?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22530",
          "name" : "22530",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017648",
          "name" : "1017648",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0571",
          "name" : "ADV-2007-0571",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32455",
          "name" : "utorrent-torrent-bo(32455)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3296",
          "name" : "3296",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a crafted announce header."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:utorrent:utorrent:1.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0928",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "virtual_calendar",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_calendar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33183",
          "name" : "33183",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24125",
          "name" : "24125",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2240",
          "name" : "2240",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459844/100/0/threaded",
          "name" : "20070210 Virtual Calendar <= (pwd.txt) Remote Password Disclosur Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32446",
          "name" : "virtualcalendar-pwd-information-disclosure(32446)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Virtual Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an encoded password via a direct request for pwd.txt."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_calendar:virtual_calendar:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0929",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "guillaume_fontaine",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_rrd_browser",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2007-February/001307.html",
          "name" : "20070213 true: [Full-disclosure] Arbitrary file disclosure vulnerability in php rrd browser < 0.2.1 (prb)",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33693",
          "name" : "33693",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2245",
          "name" : "2245",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=176562&release_id=485414",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=176562&release_id=485414",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459804/100/0/threaded",
          "name" : "20070211 Arbitrary file disclosure vulnerability in php rrd browser < 0.2.1 (prb)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32425",
          "name" : "prb-p-directory-traversal(32425)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in php rrd browser before 0.2.1 allows remote attackers to read arbitrary files via \"..\" sequences in the p parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:guillaume_fontaine:php_rrd_browser:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.2.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0930",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache_stats",
            "product" : {
              "product_data" : [ {
                "product_name" : "apache_stats",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.0.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://sourceforge.net/forum/forum.php?forum_id=660919",
          "name" : "http://sourceforge.net/forum/forum.php?forum_id=660919",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22388",
          "name" : "22388",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0559",
          "name" : "ADV-2007-0559",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP's extract function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache_stats:apache_stats:0.0.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache_stats:apache_stats:0.0.2_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2011-03-08T02:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0931",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alcatel-lucent",
            "product" : {
              "product_data" : [ {
                "product_name" : "omniaccess_wireless",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "43xx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6000",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "aruba",
            "product" : {
              "product_data" : [ {
                "product_name" : "mobility_controller",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "200",
                    "version_affected" : "="
                  }, {
                    "version_value" : "800",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2400",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6000",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052380.html",
          "name" : "20070213 Aruba Mobility Controller Management Buffer Overflow",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33184",
          "name" : "33184",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24144",
          "name" : "24144",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2244",
          "name" : "2244",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/319913",
          "name" : "VU#319913",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459928/100/0/threaded",
          "name" : "20070213 Aruba Mobility Controller Management Buffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22538",
          "name" : "22538",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32459",
          "name" : "aruba-management-interface-bo(32459)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via long credential strings."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:alcatel-lucent:omniaccess_wireless:43xx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:alcatel-lucent:omniaccess_wireless:6000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:aruba:mobility_controller:200:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:aruba:mobility_controller:800:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:aruba:mobility_controller:2400:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:aruba:mobility_controller:6000:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0932",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alcatel-lucent",
            "product" : {
              "product_data" : [ {
                "product_name" : "omniaccess_wireless",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "43xx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6000",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "aruba",
            "product" : {
              "product_data" : [ {
                "product_name" : "mobility_controller",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "200",
                    "version_affected" : "="
                  }, {
                    "version_value" : "800",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2400",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6000",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052382.html",
          "name" : "20070213 Aruba Networks - Unauthorized Administrative and WLAN Access through Guest Account",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://osvdb.org/33185",
          "name" : "33185",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24144",
          "name" : "24144",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2243",
          "name" : "2243",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/613833",
          "name" : "VU#613833",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459927/100/0/threaded",
          "name" : "20070213 Aruba Networks - Unauthorized Administrative and WLAN Access through Guest Account",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22538",
          "name" : "22538",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32461",
          "name" : "aruba-guestaccount-privilege-escalation(32461)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:alcatel-lucent:omniaccess_wireless:43xx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:alcatel-lucent:omniaccess_wireless:6000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:aruba:mobility_controller:200:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:aruba:mobility_controller:800:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:aruba:mobility_controller:2400:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:aruba:mobility_controller:6000:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-14T11:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0933",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/36160",
          "name" : "36160",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25602",
          "name" : "25602",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.blackhat.com/presentations/bh-europe-07/Butti/Presentation/bh-eu-07-Butti.pdf",
          "name" : "http://www.blackhat.com/presentations/bh-europe-07/Butti/Presentation/bh-eu-07-Butti.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24438",
          "name" : "24438",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34831",
          "name" : "dlink-tim-information-bo(34831)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the wireless driver 6.0.0.18 for D-Link DWL-G650+ (Rev. A1) on Windows XP allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a beacon frame with a long TIM Information Element."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:d-link:dwl-g650\\+:firmware_6.0.0.18:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-06-05T21:30Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0934",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "visio",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2002",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35342",
          "name" : "35342",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25619",
          "name" : "25619",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/471947/100/0/threaded",
          "name" : "SSRT071438",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24349",
          "name" : "24349",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018227",
          "name" : "1018227",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-163A.html",
          "name" : "TA07-163A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2150",
          "name" : "ADV-2007-2150",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-030",
          "name" : "MS07-030",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/34607",
          "name" : "visio-version-code-execution(34607)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1925",
          "name" : "oval:org.mitre.oval:def:1925",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visio:2002:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-06-12T19:30Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0935",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0936",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "visio",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2002",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35343",
          "name" : "35343",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25619",
          "name" : "25619",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/471947/100/0/threaded",
          "name" : "SSRT071438",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24384",
          "name" : "24384",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018227",
          "name" : "1018227",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-163A.html",
          "name" : "TA07-163A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2150",
          "name" : "ADV-2007-2150",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-030",
          "name" : "MS07-030",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1369",
          "name" : "oval:org.mitre.oval:def:1369",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka \"Visio Document Packaging Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visio:2002:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-06-12T19:30Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0937",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0938",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "content_management_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2001",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24819",
          "name" : "24819",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/434137",
          "name" : "VU#434137",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/34006",
          "name" : "34006",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/466331/100/200/threaded",
          "name" : "HPSBST02208",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22861",
          "name" : "22861",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017894",
          "name" : "1017894",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1322",
          "name" : "ADV-2007-1322",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-018",
          "name" : "MS07-018",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32736",
          "name" : "mcms-http-get-code-execution(32736)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2001",
          "name" : "oval:org.mitre.oval:def:2001",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the \"CMS Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:content_management_server:2001:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:content_management_server:2002:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-10T21:19Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0939",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "content_management_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2001",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/24819",
          "name" : "24819",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34007",
          "name" : "34007",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/466331/100/200/threaded",
          "name" : "HPSBST02208",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22860",
          "name" : "22860",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017894",
          "name" : "1017894",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1322",
          "name" : "ADV-2007-1322",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-018",
          "name" : "MS07-018",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1575",
          "name" : "oval:org.mitre.oval:def:1575",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka \"Cross-site Scripting and Spoofing Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:content_management_server:2001:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:content_management_server:2002:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-04-10T21:19Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0940",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "biztalk_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "capicom",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/25185",
          "name" : "25185",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/866305",
          "name" : "VU#866305",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/34397",
          "name" : "34397",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23782",
          "name" : "23782",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018016",
          "name" : "1018016",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018017",
          "name" : "1018017",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1713",
          "name" : "ADV-2007-1713",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-028",
          "name" : "MS07-028",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32739",
          "name" : "ms-capicom-code-execution(32739)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1670",
          "name" : "oval:org.mitre.oval:def:1670",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the \"CAPICOM.Certificates Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:biztalk_server:2004:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:biztalk_server:2004:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:capicom:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-05-08T23:19Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0941",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0942",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23769",
          "name" : "23769",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/34399",
          "name" : "34399",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018019",
          "name" : "1018019",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1712",
          "name" : "ADV-2007-1712",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027",
          "name" : "MS07-027",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33252",
          "name" : "ie-chtskdic-com-code-execution(33252)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1939",
          "name" : "oval:org.mitre.oval:def:1939",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and possibly 7 on Windows Vista does not properly \"instantiate certain COM objects as ActiveX controls,\" which allows remote attackers to execute arbitrary code via a crafted COM object from chtskdic.dll."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.0.1:sp4:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional_x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:itanium:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:gold:x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional_x64:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-05-08T23:19Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0943",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/26419",
          "name" : "26419",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1018562",
          "name" : "1018562",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.nsfocus.com/english/homepage/research/0701.htm",
          "name" : "http://www.nsfocus.com/english/homepage/research/0701.htm",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/36397",
          "name" : "36397",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25288",
          "name" : "25288",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-226A.html",
          "name" : "TA07-226A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2869",
          "name" : "ADV-2007-2869",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045",
          "name" : "MS07-045",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1673",
          "name" : "oval:org.mitre.oval:def:1673",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-08-14T21:17Z",
    "lastModifiedDate" : "2018-10-12T21:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0944",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23769",
          "name" : "23769",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34400",
          "name" : "34400",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/467989/100/0/threaded",
          "name" : "20070508 ZDI-07-027: Microsoft Internet Explorer Table Column Deletion Memory Corruption Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23771",
          "name" : "23771",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018019",
          "name" : "1018019",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1712",
          "name" : "ADV-2007-1712",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-07-027.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-07-027.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027",
          "name" : "MS07-027",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33253",
          "name" : "ie-object-array-code-execution(33253)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1722",
          "name" : "oval:org.mitre.oval:def:1722",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; and 6 on Windows XP SP2, or Windows Server 2003 SP1 or SP2 allows remote attackers to execute arbitrary code by calling deleteCell on a named table row in a named table column, then accessing the column, which causes Internet Explorer to access previously deleted objects, aka the \"Uninitialized Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:sp4:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-05-08T23:19Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0945",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23769",
          "name" : "23769",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34401",
          "name" : "34401",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23769",
          "name" : "23769",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018019",
          "name" : "1018019",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1712",
          "name" : "ADV-2007-1712",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027",
          "name" : "MS07-027",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1463",
          "name" : "oval:org.mitre.oval:def:1463",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and 7 on Windows Vista allows remote attackers to execute arbitrary code via certain property methods that may trigger memory corruption, aka \"Property Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:sp1:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-05-08T23:19Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0946",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23769",
          "name" : "23769",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/34402",
          "name" : "34402",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23770",
          "name" : "23770",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018019",
          "name" : "1018019",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1712",
          "name" : "ADV-2007-1712",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027",
          "name" : "MS07-027",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33255",
          "name" : "ie-html-memory-code-execution(33255)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1441",
          "name" : "oval:org.mitre.oval:def:1441",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two \"HTML Objects Memory Corruption Vulnerabilities\" and a different issue than CVE-2007-0947."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-05-08T23:19Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0947",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/23769",
          "name" : "23769",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2007-36/advisory/",
          "name" : "http://secunia.com/secunia_research/2007-36/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/34403",
          "name" : "34403",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/468871/100/200/threaded",
          "name" : "HPSBST02214",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23772",
          "name" : "23772",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018019",
          "name" : "1018019",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-128A.html",
          "name" : "TA07-128A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1712",
          "name" : "ADV-2007-1712",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027",
          "name" : "MS07-027",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33256",
          "name" : "ie-html-memory-code-execution-variant(33256)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2048",
          "name" : "oval:org.mitre.oval:def:2048",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two \"HTML Objects Memory Corruption Vulnerabilities\" and a different issue than CVE-2007-0946."
        }, {
          "lang" : "en",
          "value" : "FrSIRT has noted the following: Multiple vulnerabilities have been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to take complete control of an affected system."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp2:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-05-08T23:19Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0948",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_pc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "virtual_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/26444",
          "name" : "26444",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25298",
          "name" : "25298",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1018567",
          "name" : "1018567",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-226A.html",
          "name" : "TA07-226A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2873",
          "name" : "ADV-2007-2873",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-049",
          "name" : "MS07-049",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1259",
          "name" : "oval:org.mitre.oval:def:1259",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to \"interaction and initialization of components.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:virtual_pc:6.1:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:virtual_pc:7:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:virtual_pc:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:virtual_server:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:virtual_server:2005:r2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2007-08-14T22:17Z",
    "lastModifiedDate" : "2018-10-12T21:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0949",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "itinysoft_studio",
            "product" : {
              "product_data" : [ {
                "product_name" : "total_video_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.03",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33187",
          "name" : "33187",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23999",
          "name" : "23999",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22553",
          "name" : "22553",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32479",
          "name" : "totalvideoplayer-m3u-bo(32479)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5032",
          "name" : "5032",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/5077",
          "name" : "5077",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers to execute arbitrary code via a M3U playlist file that contains a long file name. NOTE: it was later reported that 1.20 and 1.30 are also affected."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:itinysoft_studio:total_video_player:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.03"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-15T02:28Z",
    "lastModifiedDate" : "2017-10-11T01:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0950",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fullaspsite",
            "product" : {
              "product_data" : [ {
                "product_name" : "asp_hosting_site",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33720",
          "name" : "33720",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2250",
          "name" : "2250",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459979/100/0/threaded",
          "name" : "20070213 Fullaspsite Shop (tr) Xss & SqL &#304;nj. VulnZ.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22545",
          "name" : "22545",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32469",
          "name" : "fullaspsite-listmain-xss(32469)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to inject arbitrary web script or HTML via the cat parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fullaspsite:asp_hosting_site:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-15T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0951",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fullaspsite",
            "product" : {
              "product_data" : [ {
                "product_name" : "asp_hosting_site",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33721",
          "name" : "33721",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/2250",
          "name" : "2250",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/459979/100/0/threaded",
          "name" : "20070213 Fullaspsite Shop (tr) Xss & SqL &#304;nj. VulnZ.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22545",
          "name" : "22545",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32470",
          "name" : "fullaspsite-listmain-sql-injection(32470)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to execute arbitrary SQL commands via the cat parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fullaspsite:asp_hosting_site:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-15T02:28Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0952",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scriptsez.net",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_calendar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33182",
          "name" : "33182",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24125",
          "name" : "24125",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22536",
          "name" : "22536",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32448",
          "name" : "virtualcalendar-unspecified-xss(32448)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Virtual Calendar allow remote attackers to inject arbitrary web script or HTML via the (1) t and (2) yr parameters, and the (3) sho parameter when the m parameter is outside the intended range."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scriptsez.net:virtual_calendar:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-15T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0953",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "atmail",
            "product" : {
              "product_data" : [ {
                "product_name" : "atmail_webmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.61",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.atmail.com/?p=410",
          "name" : "http://kb.atmail.com/?p=410",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lostmon.blogspot.com/2007/02/mail-searchpl-keywords-variable-cross.html",
          "name" : "http://lostmon.blogspot.com/2007/02/mail-searchpl-keywords-variable-cross.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/33193",
          "name" : "33193",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24155",
          "name" : "24155",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22552",
          "name" : "22552",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0603",
          "name" : "ADV-2007-0603",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32483",
          "name" : "@mail-search-xss(32483)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.pl in @Mail 4.61 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atmail:atmail_webmail:4.3:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atmail:atmail_webmail:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atmail:atmail_webmail:4.11:*:freebsd:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atmail:atmail_webmail:4.11:*:hp-ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atmail:atmail_webmail:4.11:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atmail:atmail_webmail:4.11:*:mac_os_x:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atmail:atmail_webmail:4.11:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atmail:atmail_webmail:4.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atmail:atmail_webmail:4.61:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-15T02:28Z",
    "lastModifiedDate" : "2017-07-29T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0954",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mohachat",
            "product" : {
              "product_data" : [ {
                "product_name" : "moha_chat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1b7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://mohachat.sourceforge.net/download/release_notes/#0.1b8",
          "name" : "http://mohachat.sourceforge.net/download/release_notes/#0.1b8",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://osvdb.org/31934",
          "name" : "31934",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0599",
          "name" : "ADV-2007-0599",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "MOHA Chat 0.1b7 and earlier does not require authentication for use of the plug in API, which has unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mohachat:moha_chat:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.1b7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-15T02:28Z",
    "lastModifiedDate" : "2011-03-08T02:51Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0955",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mailenable",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailenable",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.35",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0321.html",
          "name" : "20070214 MailEnable DoS POC",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0333.html",
          "name" : "20070214 MailEnable DoS POC-2",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052427.html",
          "name" : "20071214 MailEnable DoS POC",
          "refsource" : "FULLDISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://osvdb.org/33195",
          "name" : "33195",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/24139",
          "name" : "24139",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/2249",
          "name" : "2249",
          "refsource" : "SREASON",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0614",
          "name" : "ADV-2007-0614",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32482",
          "name" : "mailenable-ntlm-dos(32482)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (application crash) via certain base64-encoded data following an AUTHENTICATE NTLM command to the imap port (143/tcp), which results in an out-of-bounds read."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable:*:*:*:*:professional:*:*:*",
          "versionEndIncluding" : "2.35"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-15T02:28Z",
    "lastModifiedDate" : "2019-10-02T20:13Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0956",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mit",
            "product" : {
              "product_data" : [ {
                "product_name" : "kerberos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5-1.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "rpath",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070401-01-P.asc",
          "name" : "20070401-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Apr/0001.html",
          "name" : "SUSE-SA:2007:025",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24706",
          "name" : "24706",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24735",
          "name" : "24735",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24736",
          "name" : "24736",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24740",
          "name" : "24740",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24750",
          "name" : "24750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24755",
          "name" : "24755",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24757",
          "name" : "24757",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24785",
          "name" : "24785",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24786",
          "name" : "24786",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24817",
          "name" : "24817",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200704-02.xml",
          "name" : "GLSA-200704-02",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102867-1",
          "name" : "102867",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-001-telnetd.txt",
          "name" : "http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-001-telnetd.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1276",
          "name" : "DSA-1276",
          "refsource" : "DEBIAN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/220816",
          "name" : "VU#220816",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:077",
          "name" : "MDKSA-2007:077",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0095.html",
          "name" : "RHSA-2007:0095",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464590/100/0/threaded",
          "name" : "20070403 MITKRB5-SA-2007-001: telnetd allows login as arbitrary user [CVE-2007-0956]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464666/100/0/threaded",
          "name" : "20070404 rPSA-2007-0063-1 krb5 krb5-server krb5-services krb5-test krb5-workstation",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464814/30/7170/threaded",
          "name" : "20070405 FLEA-2007-0008-1: krb5",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23281",
          "name" : "23281",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017848",
          "name" : "1017848",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-449-1",
          "name" : "USN-449-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-093B.html",
          "name" : "TA07-093B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1218",
          "name" : "ADV-2007-1218",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1249",
          "name" : "ADV-2007-1249",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33414",
          "name" : "kerberos-telnet-security-bypass(33414)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10046",
          "name" : "oval:org.mitre.oval:def:10046",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882."
        }, {
          "lang" : "en",
          "value" : "The vendor will address this issue in the upcoming krb5-1.6.1 release."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:rpath:linux:1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5-1.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-06T01:19Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0957",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mit",
            "product" : {
              "product_data" : [ {
                "product_name" : "kerberos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5-1.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20070401-01-P.asc",
          "name" : "20070401-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2007-Apr/0001.html",
          "name" : "SUSE-SA:2007:025",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24706",
          "name" : "24706",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24735",
          "name" : "24735",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24736",
          "name" : "24736",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24740",
          "name" : "24740",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24750",
          "name" : "24750",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24757",
          "name" : "24757",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24785",
          "name" : "24785",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24786",
          "name" : "24786",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24798",
          "name" : "24798",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24817",
          "name" : "24817",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25464",
          "name" : "25464",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200704-02.xml",
          "name" : "GLSA-200704-02",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102930-1",
          "name" : "102930",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-002-syslog.txt",
          "name" : "http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-002-syslog.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1276",
          "name" : "DSA-1276",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/704024",
          "name" : "VU#704024",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:077",
          "name" : "MDKSA-2007:077",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0095.html",
          "name" : "RHSA-2007:0095",
          "refsource" : "REDHAT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464592/100/0/threaded",
          "name" : "20070403 MITKRB5-SA-2007-002: KDC, kadmind stack overflow in krb5_klog_syslog [CVE-2007-0957]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464666/100/0/threaded",
          "name" : "20070404 rPSA-2007-0063-1 krb5 krb5-server krb5-services krb5-test krb5-workstation",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/464814/30/7170/threaded",
          "name" : "20070405 FLEA-2007-0008-1: krb5",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/23285",
          "name" : "23285",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017849",
          "name" : "1017849",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-449-1",
          "name" : "USN-449-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-093B.html",
          "name" : "TA07-093B",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1218",
          "name" : "ADV-2007-1218",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1250",
          "name" : "ADV-2007-1250",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1983",
          "name" : "ADV-2007-1983",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33411",
          "name" : "kerberos-krb5klogsyslog-bo(33411)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10757",
          "name" : "oval:org.mitre.oval:def:10757",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via crafted arguments, possibly involving certain format string specifiers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mit:kerberos:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5-1.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-04-06T01:19Z",
    "lastModifiedDate" : "2018-10-16T16:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0958",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.17.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.18.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.19.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.20",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/35930",
          "name" : "35930",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2007-0488.html",
          "name" : "RHSA-2007:0488",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24482",
          "name" : "24482",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24752",
          "name" : "24752",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24777",
          "name" : "24777",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25078",
          "name" : "25078",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25714",
          "name" : "25714",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25838",
          "name" : "25838",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26289",
          "name" : "26289",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1286",
          "name" : "DSA-1286",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1304",
          "name" : "DSA-1304",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt",
          "name" : "http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20",
          "name" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:060",
          "name" : "MDKSA-2007:060",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:078",
          "name" : "MDKSA-2007:078",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0099.html",
          "name" : "RHSA-2007:0099",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22903",
          "name" : "22903",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-451-1",
          "name" : "USN-451-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10343",
          "name" : "oval:org.mitre.oval:def:10343",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Linux kernel 2.6.x before 2.6.20 allows local users to read unreadable binaries by using the interpreter (PT_INTERP) functionality and triggering a core dump, a variant of CVE-2004-1073."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.17.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.18.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.19.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.20:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-15T18:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0959",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "asa_5500",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2(2)",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pix_firewall_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2(2)",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33062",
          "name" : "33062",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24160",
          "name" : "24160",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml",
          "name" : "20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22561",
          "name" : "22561",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22562",
          "name" : "22562",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017651",
          "name" : "1017651",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017652",
          "name" : "1017652",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0608",
          "name" : "ADV-2007-0608",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32488",
          "name" : "cisco-pix-asa-tcp-dos(32488)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:asa_5500:7.2\\(2\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:7.2\\(2\\):*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-16T00:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0960",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "asa_5500",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2(2)",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pix_firewall_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2(2)",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33063",
          "name" : "33063",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24160",
          "name" : "24160",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24179",
          "name" : "24179",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml",
          "name" : "20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22561",
          "name" : "22561",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22562",
          "name" : "22562",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017651",
          "name" : "1017651",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017652",
          "name" : "1017652",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0608",
          "name" : "ADV-2007-0608",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32489",
          "name" : "cisco-pix-asa-local-privilege-escalation(32489)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:asa_5500:7.2\\(2\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:7.2\\(2\\):*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-16T00:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0961",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "asa_5500",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pix_firewall_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/33054",
          "name" : "33054",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24160",
          "name" : "24160",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24179",
          "name" : "24179",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24180",
          "name" : "24180",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1017651",
          "name" : "1017651",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml",
          "name" : "20070214 Multiple Vulnerabilities in Firewall Services Module",
          "refsource" : "CISCO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml",
          "name" : "20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances",
          "refsource" : "CISCO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/430969",
          "name" : "VU#430969",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22561",
          "name" : "22561",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/22562",
          "name" : "22562",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id?1017652",
          "name" : "1017652",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0608",
          "name" : "ADV-2007-0608",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32487",
          "name" : "cisco-pix-asa-sip-dos(32487)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/32501",
          "name" : "cisco-fwsm-sip-dos(32501)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco PIX 500 and ASA 5500 Series Security Appliances 6.x before 6.3(5.115), 7.0 before 7.0(5.2), and 7.1 before 7.1(2.5), and the FWSM 3.x before 3.1(3.24), when the \"inspect sip\" option is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed SIP packets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:asa_5500:6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:asa_5500:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:asa_5500:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:asa_5500:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:7.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2007-02-16T00:28Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2007-0962",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "asa_5500",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "firewall_services_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pix_firewall_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
        